ASSOCIATED DRATA CONTROL
This test is part of the Customer Data is Encrypted at Rest control that ensures your company stores customer data in databases that are encrypted at rest.
WHAT TO DO IF A TEST FAILS
If Drata finds production databases that are not encrypted at rest the test will fail. With a failed test you will receive a list of production databases that do not have encryption enabled.
To remediate a failed test, you will need to properly configure these databases to enable encryption.
STEPS FOR PASSING
To ensure a validated state when testing for encryption at rest, please follow the steps listed in the table below. Once the provider steps have been completed, navigate back to Drata and execute the test.
Provider / Technology | Provider Steps |
Atlas |
|
AWS - DynamoDB | By default, DynamoDB is fully encrypted at rest. |
AWS - OpenSearch (formerly Elasticsearch) | Step 1 - Choose Deployment Type
Step 2 - Configure Domain
Step 3 - Configure Access and Security
|
AWS - Elasticache for Redis |
|
GCP - SQL |
|
GCP - Datastore |
|
GCP - Memorystore |
|