πΌ [ES.1] Elasticsearch domains should have encryption at-rest enabled
- Contextual name: πΌ [ES.1] Elasticsearch domains should have encryption at-rest enabled
- ID:
/frameworks/aws-fsbp-v1.0.0/es/01
- Located in: πΌ Elasticsearch
Descriptionβ
For an added layer of security for your sensitive data in OpenSearch, you should configure your OpenSearch to be encrypted at rest. Elasticsearch domains offer encryption of data at rest. The feature uses AWS KMS to store and manage your encryption keys. To perform the encryption, it uses the Advanced Encryption Standard algorithm with 256-bit keys (AES-256).
Similarβ
- AWS Security Hub
- Internal
- ID:
dec-c-852b1f1b
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST SP 800-53 Revision 5 β πΌ CA-9(1) Internal System Connections _ Compliance Checks | 20 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ CM-3(6) Configuration Change Control _ Cryptography Management | 6 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-7(10) Boundary Protection _ Prevent Exfiltration | 6 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-13 Cryptographic Protection | 4 | 13 | ||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-28 Protection of Information at Rest | 3 | 16 | 25 | |
πΌ NIST SP 800-53 Revision 5 β πΌ SC-28(1) Protection of Information at Rest _ Cryptographic Protection | 10 | 14 | ||
πΌ NIST SP 800-53 Revision 5 β πΌ SI-7(6) Software, Firmware, and Information Integrity _ Cryptographic Protection | 12 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|