Description
Graph databases can hold relationship data, user connections and business data that need encryption at rest. Neptune encryption protects cluster storage, logs, backups and snapshots.
An actually unencrypted cluster lacks this storage protection. IAM database authentication and network or transport protection require separate management.
Potential impact
Unauthorized acquisition of unencrypted storage or backups can expose sensitive graph data. Database encryption requirements may also be unmet. If a KMS key in use becomes unavailable, data access and recovery can be affected.
Remediation
- Explicitly set
storage_encrypted = truefor new clusters and verify organizational KMS key and permission requirements. - Changing a setting alone cannot encrypt an existing unencrypted cluster. Plan migration by restoring an unencrypted snapshot to a new encrypted cluster, specifying the KMS key during restore.
- Verify Terraform replacement, data consistency, application connections and backup recovery, preserving the original data and required keys.
Examples
These are new-cluster configuration excerpts. Prepare required instances and networking separately.
Before
resource "aws_neptune_cluster" "neptune_cluster" {
cluster_identifier = "neptune-cluster-demo"
engine = "neptune"
iam_database_authentication_enabled = true
storage_encrypted = false
}
Enabling IAM authentication does not compensate for disabled encryption at rest.
After
resource "aws_neptune_cluster" "neptune_cluster" {
cluster_identifier = "neptune-cluster-demo"
engine = "neptune"
iam_database_authentication_enabled = true
storage_encrypted = true
}
This requests encryption at rest for a new cluster. It does not replace a migration procedure for existing data.