Medium
RedshiftServerless
Regional
Redshift Serverless namespaces should be encrypted with customer managed AWS KMS keys
Description
Flags Amazon Redshift Serverless namespaces that are not encrypted with a customer-managed KMS key. AWS-owned and AWS-managed keys cannot be audited via key policies.
Remediation
Re-key each affected namespace with a customer-managed CMK.
Steps
- Open the Amazon Redshift Serverless console and select the namespace.
- Choose Edit, then under Encryption choose a customer-managed KMS key.
- Save the changes.