Description
Neptune encryption at rest protects graph data and associated logs, backups and snapshots. An unencrypted cluster lacks this layer of protection against unauthorized access to underlying storage. Encryption of logs exported to CloudWatch must be configured separately.
Storage encryption and IAM database authentication provide different protections. Even with encrypted storage, permissions and network controls must limit data access to the required users and applications.
Potential impact
Unauthorized acquisition of stored data or backups can expose personal information or business relationships in the graph. It may also leave organizational data-protection requirements unmet.
Remediation
Set StorageEncrypted: true for new clusters. If a separate KMS key is required, prepare the key and permissions before creation; otherwise verify that the default key meets requirements. Protect keys and backups because losing access to the key can interrupt database operation.
An existing unencrypted cluster cannot be encrypted directly. Use a supported migration, such as specifying a KMS key when restoring a snapshot into a new encrypted cluster. Preserve the source and verify data consistency, new connection endpoints and application cutover.
Examples
These compare creation settings for new clusters. DB instances, subnets and security groups require separate configuration. Snapshot retention policies preserve backups but do not migrate data or switch the service.
Before
Resources:
NeptuneDBCluster:
Type: AWS::Neptune::DBCluster
DeletionPolicy: Snapshot
UpdateReplacePolicy: Snapshot
Properties:
IamAuthEnabled: true
Port: 8182
StorageEncrypted: false
Enabling IAM authentication does not also enable encryption at rest.
After
Resources:
NeptuneDBCluster:
Type: AWS::Neptune::DBCluster
DeletionPolicy: Snapshot
UpdateReplacePolicy: Snapshot
Properties:
IamAuthEnabled: true
Port: 8182
StorageEncrypted: true
This enables encryption at rest. Without a separately specified key, Neptune uses its default encryption key in the Region, aws/rds.