Description
Disabling encryption at rest or in transit in an EMR security configuration removes the corresponding EMR encryption protection. Actual coverage also depends on the applications in use and separate storage encryption settings.
Potential impact
Unprotected stored data or network traffic can be more exposed to disclosure.
Remediation
Enable EnableAtRestEncryption and EnableInTransitEncryption, and configure the key provider for the storage in use and certificates for encryption in transit. Attach the security configuration to the actual cluster.
Examples
The excerpts show only the two enabling flags. They are not a complete encryption configuration: add the required key and certificate settings under AtRestEncryptionConfiguration and InTransitEncryptionConfiguration.
Before
Resources:
EMRSecurityConfiguration:
Type: AWS::EMR::SecurityConfiguration
Properties:
SecurityConfiguration:
EncryptionConfiguration:
EnableInTransitEncryption: false
EnableAtRestEncryption: false
After
Resources:
EMRSecurityConfiguration:
Type: AWS::EMR::SecurityConfiguration
Properties:
SecurityConfiguration:
EncryptionConfiguration:
EnableInTransitEncryption: true
EnableAtRestEncryption: true