Medium RedshiftServerless Regional

Redshift Serverless namespaces should be encrypted with customer managed AWS KMS keys

Description

Flags Amazon Redshift Serverless namespaces that are not encrypted with a customer-managed KMS key. AWS-owned and AWS-managed keys cannot be audited via key policies.


Remediation

Re-key each affected namespace with a customer-managed CMK.

Steps

  1. Open the Amazon Redshift Serverless console and select the namespace.
  2. Choose Edit, then under Encryption choose a customer-managed KMS key.
  3. Save the changes.