rspec/rules/S6308/description.adoc

10 lines
464 B
Plaintext
Raw Normal View History

Amazon Elasticsearch Service (ES) is a managed service to host Elasticsearch instances.
To harden domain (cluster) data in case of unauthorized access, ES provides data-at-rest encryption if the Elasticsearch version is 5.1 or above. Enabling encryption at rest will help protect:
* Indices
* Logs
* Swap files
* Data in the application directory
* Automated snapshots
Thus, if adversaries gain physical access to the storage medium, they cannot access the data.