Medium
RDS
Regional
RDS DB instances should have encryption at-rest enabled
CISNISTISO 27001HIPAA
Description
Checks whether the RDS DB instances have encryption at-rest enabled.
Remediation
To enable encryption at-rest for the identified RDS DB instance, follow these steps:
Steps
- Log in to the AWS Management Console and open the Amazon RDS console.
- In the navigation pane, click on 'Databases'.
- Select the RDS DB instance that requires encryption at-rest.
- Choose 'Modify'.
- In the 'Modify DB Instance' page, scroll down to the 'Database options' section.
- Find the 'Encryption' option and select 'Enable Encryption'.
- Choose an encryption key from the available AWS Key Management Service (KMS) keys. If you do not have a KMS key, you can create one.
- Scroll to the bottom of the page and click on 'Continue'.
- Review your changes. You can apply them immediately or during the next maintenance window.
- Click 'Modify DB Instance' to save the changes.
Compliance
CISNISTISO 27001HIPAA