Description
ElastiCache Redis OSS encryption at rest protects data written to disk during synchronization, backup and swap operations, as well as backups. If a cache holds sessions, tokens or personal information, its stored copies also need protection. Encryption at rest does not replace encrypted client connections or user authentication.
Potential impact
Unauthorized acquisition of unencrypted stored data or backups increases the risk of sensitive information exposure. It can also leave organizational data-protection requirements for the cache unmet.
Remediation
Specify AtRestEncryptionEnabled: true for new replication groups and review the required KMS key and permissions. This option defaults to false for Redis OSS, so verify the actual state.
The setting cannot be toggled on an existing group. Restore or migrate data into a new encrypted group, verify application connectivity and data consistency, then switch clients over. Prepare backup and recovery plans before the cutover, and configure encryption in transit and authentication separately.
Examples
Supply a cache subnet group in the actual VPC and security groups allowing only required access. These examples compare single-node creation settings; they do not configure high availability or migrate existing data.
Before
Parameters:
CacheSubnetGroupName:
Type: String
CacheSecurityGroups:
Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
ReplicationGroup:
Type: AWS::ElastiCache::ReplicationGroup
Properties:
ReplicationGroupDescription: example
AtRestEncryptionEnabled: false
Engine: redis
CacheNodeType: cache.t3.micro
NumCacheClusters: 1
CacheSubnetGroupName: !Ref CacheSubnetGroupName
SecurityGroupIds: !Ref CacheSecurityGroups
After
Parameters:
CacheSubnetGroupName:
Type: String
CacheSecurityGroups:
Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
ReplicationGroup:
Type: AWS::ElastiCache::ReplicationGroup
Properties:
ReplicationGroupDescription: example
AtRestEncryptionEnabled: true
Engine: redis
CacheNodeType: cache.t3.micro
NumCacheClusters: 1
CacheSubnetGroupName: !Ref CacheSubnetGroupName
SecurityGroupIds: !Ref CacheSecurityGroups