Neptune database cluster with storage encryption disabled

Encrypt Neptune storage and backups, and plan restoration and cutover for existing clusters.

Description

Neptune encryption at rest protects graph data and associated logs, backups and snapshots. An unencrypted cluster lacks this layer of protection against unauthorized access to underlying storage. Encryption of logs exported to CloudWatch must be configured separately.

Storage encryption and IAM database authentication provide different protections. Even with encrypted storage, permissions and network controls must limit data access to the required users and applications.

Potential impact

Unauthorized acquisition of stored data or backups can expose personal information or business relationships in the graph. It may also leave organizational data-protection requirements unmet.

Remediation

Set StorageEncrypted: true for new clusters. If a separate KMS key is required, prepare the key and permissions before creation; otherwise verify that the default key meets requirements. Protect keys and backups because losing access to the key can interrupt database operation.

An existing unencrypted cluster cannot be encrypted directly. Use a supported migration, such as specifying a KMS key when restoring a snapshot into a new encrypted cluster. Preserve the source and verify data consistency, new connection endpoints and application cutover.

Examples

These compare creation settings for new clusters. DB instances, subnets and security groups require separate configuration. Snapshot retention policies preserve backups but do not migrate data or switch the service.

Before

yaml
Resources:
  NeptuneDBCluster:
    Type: AWS::Neptune::DBCluster
    DeletionPolicy: Snapshot
    UpdateReplacePolicy: Snapshot
    Properties:
      IamAuthEnabled: true
      Port: 8182
      StorageEncrypted: false

Enabling IAM authentication does not also enable encryption at rest.

After

yaml
Resources:
  NeptuneDBCluster:
    Type: AWS::Neptune::DBCluster
    DeletionPolicy: Snapshot
    UpdateReplacePolicy: Snapshot
    Properties:
      IamAuthEnabled: true
      Port: 8182
      StorageEncrypted: true

This enables encryption at rest. Without a separately specified key, Neptune uses its default encryption key in the Region, aws/rds.

References