Medium
Kinesis
Regional
Firehose delivery streams should be encrypted at rest
NIST 800-53
Description
Ensures Firehose delivery streams are encrypted at rest using AWS KMS. Data is encrypted before being written to the stream's storage layer and decrypted on retrieval, supporting regulatory compliance.
Remediation
Enable server-side encryption for your Amazon Data Firehose delivery streams using AWS KMS.
Steps
- Navigate to the Amazon Kinesis Data Firehose console
- Select the delivery stream that needs encryption
- Edit the delivery stream configuration
- In the 'Encryption' section, enable 'Server-side encryption'
- Choose 'AWS KMS' as the encryption key source
- Select or create a KMS key for encryption
- Save the configuration changes
- Verify that the delivery stream is now encrypted at rest
Compliance
NIST 800-53