Control: AWS > PCI v3.2.1 > Elasticsearch > 2 Amazon Elasticsearch Service domains should have encryption at rest enabled
This control checks whether Amazon ES domains have encryption at rest configuration enabled.
Remediation
By default, domains do not encrypt data at rest, and you cannot configure existing domains to use the feature.
To enable the feature, you must create another domain and migrate your data. For information about creating domains, see the Amazon Elasticsearch Service Developer Guide.
Encryption of data at rest requires Amazon ES 5.1 or later. For more information about encrypting data at rest for Amazon ES, see the Amazon Elasticsearch Service Developer Guide.
PCI requirement(s): 3.4
Resource Types
This control targets the following resource types:
Category
In Your Workspace
Developers
- tmod:@turbot/aws-pciv3-2-1#/control/types/esDomainEncryptionAtRestEnabled
- tmod:@turbot/turbot#/control/categories/compliancePci
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-pciv3-2-1#/control/types/esDomainEncryptionAtRestEnabled"
Get Controls
Control Type URI
Category URI
GraphQL
CLI