logo

Database

Aws At Rest Encryption Disabled

Description

Identifies AWS ElastiCache Redis clusters that do not have at-rest encryption enabled. Unencrypted Redis clusters could expose sensitive data to unauthorized access if the underlying storage is compromised.

Weakness:

165 - Insecure service configuration - AWS

Category: Functionality Abuse

Detection Strategy

    Redis cluster is using the Redis engine type

    The AtRestEncryptionEnabled setting is set to false or is not configured

    Examines all ElastiCache clusters in the specified AWS region