Description
Encryption at rest in RDS, Aurora, DocumentDB, Neptune and Redshift protects data and associated backups or snapshots. Specify the required encryption and key management, then verify the deployed state.
Omission does not mean unencrypted storage across every service. Aurora instance encryption is managed by the cluster, while restores and replicas can inherit source settings. The current Redshift API encrypts newly created clusters by default. Absence of a customer-managed key is also different from absence of storage encryption.
Potential impact
- Actually unencrypted data or unsuitable key management may not meet data-protection requirements.
- Incorrect key permissions or unplanned resource replacement can disrupt data access and service operation.
Remediation
- Check encryption and keys on actual databases, clusters and snapshots, applying the service's creation and restore requirements. For new RDS databases, specify
StorageEncrypted: trueand an approvedKmsKeyIdwhere required. - Migrate existing unencrypted RDS instances through a supported procedure, such as copying a snapshot with encryption and restoring a new instance. Adding encryption options to a read replica of an unencrypted source is not a supported alternative.
- Review the change set, retention, backups and application cutover. Verify actual encryption and data access, while maintaining network permissions, database permissions and TLS.
Examples
These are alternatives for a new MySQL instance. Supply an instance type supported by the engine in the Region and securely managed credentials; add subnet and security-group settings for your environment. They are not a lossless encryption migration procedure for a running database.
Encryption and key not specified
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
DBInstanceClass:
Type: String
DBUsername:
Type: String
DBPassword:
Type: String
NoEcho: true
Resources:
MyDB:
Type: AWS::RDS::DBInstance
DeletionPolicy: Snapshot
UpdateReplacePolicy: Snapshot
Properties:
DBInstanceClass: !Ref DBInstanceClass
AllocatedStorage: 50
Engine: mysql
MasterUsername: !Ref DBUsername
MasterUserPassword: !Ref DBPassword
The encryption requirement is not explicit. Verify the actual setting and applicable creation defaults.
Encryption and key specified
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
DBInstanceClass:
Type: String
DBUsername:
Type: String
DBPassword:
Type: String
NoEcho: true
DatabaseKmsKeyArn:
Type: String
Resources:
MyDB:
Type: AWS::RDS::DBInstance
DeletionPolicy: Snapshot
UpdateReplacePolicy: Snapshot
Properties:
DBInstanceClass: !Ref DBInstanceClass
AllocatedStorage: 50
Engine: mysql
StorageEncrypted: true
KmsKeyId: !Ref DatabaseKmsKeyArn
MasterUsername: !Ref DBUsername
MasterUserPassword: !Ref DBPassword
This selects encryption and a key for a new instance. Supply an approved KMS key ARN in the same Region with the required permissions. Retaining snapshots does not by itself complete application-data migration.