What solution will address this issue with the LEAST operational overhead and will provide monitoring for potential future violations?

1 Comment

  1. Kathleen
    Author

    I categorize that the answer is:
    Enable SSE encryption on the S3 buckets, EBS volumes, and the RDS database. Store RDS credentials in EC2 Parameter Store. Enable a policy on the S3 bucket to deny unencrypted puts. Set up AWS Config rules to periodically check for non-encrypted S3 objects and EBS volumes, and to ensure that RDS storage is encrypted.

Leave a Reply to Kathleen Cancel reply

Your email address will not be published. Required fields are marked *

twelve + 1 =