Encryption disabled in an EMR security configuration

Configure the encryption at rest and in transit required by the EMR workload.

Description

Disabling encryption at rest or in transit in an EMR security configuration removes the corresponding EMR encryption protection. Actual coverage also depends on the applications in use and separate storage encryption settings.

Potential impact

Unprotected stored data or network traffic can be more exposed to disclosure.

Remediation

Enable EnableAtRestEncryption and EnableInTransitEncryption, and configure the key provider for the storage in use and certificates for encryption in transit. Attach the security configuration to the actual cluster.

Examples

The excerpts show only the two enabling flags. They are not a complete encryption configuration: add the required key and certificate settings under AtRestEncryptionConfiguration and InTransitEncryptionConfiguration.

Before

yaml
Resources:
  EMRSecurityConfiguration:
    Type: AWS::EMR::SecurityConfiguration
    Properties:
      SecurityConfiguration:
        EncryptionConfiguration:
          EnableInTransitEncryption: false
          EnableAtRestEncryption: false

After

yaml
Resources:
  EMRSecurityConfiguration:
    Type: AWS::EMR::SecurityConfiguration
    Properties:
      SecurityConfiguration:
        EncryptionConfiguration:
          EnableInTransitEncryption: true
          EnableAtRestEncryption: true

References