Database storage encryption needs review

Verify actual database storage encryption and keys. Distinguish service defaults, cluster settings and properties inherited during restores or replication.

Description

Encryption at rest in RDS, Aurora, DocumentDB, Neptune and Redshift protects data and associated backups or snapshots. Specify the required encryption and key management, then verify the deployed state.

Omission does not mean unencrypted storage across every service. Aurora instance encryption is managed by the cluster, while restores and replicas can inherit source settings. The current Redshift API encrypts newly created clusters by default. Absence of a customer-managed key is also different from absence of storage encryption.

Potential impact

  • Actually unencrypted data or unsuitable key management may not meet data-protection requirements.
  • Incorrect key permissions or unplanned resource replacement can disrupt data access and service operation.

Remediation

  • Check encryption and keys on actual databases, clusters and snapshots, applying the service's creation and restore requirements. For new RDS databases, specify StorageEncrypted: true and an approved KmsKeyId where required.
  • Migrate existing unencrypted RDS instances through a supported procedure, such as copying a snapshot with encryption and restoring a new instance. Adding encryption options to a read replica of an unencrypted source is not a supported alternative.
  • Review the change set, retention, backups and application cutover. Verify actual encryption and data access, while maintaining network permissions, database permissions and TLS.

Examples

These are alternatives for a new MySQL instance. Supply an instance type supported by the engine in the Region and securely managed credentials; add subnet and security-group settings for your environment. They are not a lossless encryption migration procedure for a running database.

Encryption and key not specified

yaml
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
  DBInstanceClass:
    Type: String
  DBUsername:
    Type: String
  DBPassword:
    Type: String
    NoEcho: true
Resources:
  MyDB:
    Type: AWS::RDS::DBInstance
    DeletionPolicy: Snapshot
    UpdateReplacePolicy: Snapshot
    Properties:
      DBInstanceClass: !Ref DBInstanceClass
      AllocatedStorage: 50
      Engine: mysql
      MasterUsername: !Ref DBUsername
      MasterUserPassword: !Ref DBPassword

The encryption requirement is not explicit. Verify the actual setting and applicable creation defaults.

Encryption and key specified

yaml
AWSTemplateFormatVersion: "2010-09-09"
Parameters:
  DBInstanceClass:
    Type: String
  DBUsername:
    Type: String
  DBPassword:
    Type: String
    NoEcho: true
  DatabaseKmsKeyArn:
    Type: String
Resources:
  MyDB:
    Type: AWS::RDS::DBInstance
    DeletionPolicy: Snapshot
    UpdateReplacePolicy: Snapshot
    Properties:
      DBInstanceClass: !Ref DBInstanceClass
      AllocatedStorage: 50
      Engine: mysql
      StorageEncrypted: true
      KmsKeyId: !Ref DatabaseKmsKeyArn
      MasterUsername: !Ref DBUsername
      MasterUserPassword: !Ref DBPassword

This selects encryption and a key for a new instance. Supply an approved KMS key ARN in the same Region with the required permissions. Retaining snapshots does not by itself complete application-data migration.

References