QuestionQ19

Security and Compliance

A company uses Amazon RDS for every database in its AWS accounts. The company uses AWS Control Tower to create a landing zone with an audit and logging account. For compliance, all databases must be encrypted at rest. The company's security engineer needs to be notified of any noncompliant databases in the company’s accounts.

Which solution meets these requirements with the MOST operational efficiency?

Explanation

AWS Control Tower provides a strongly recommended detective control that detects Amazon RDS DB instances whose storage is not encrypted at rest. The control is implemented by the AWS Config managed rule RDS_STORAGE_ENCRYPTED. Enabling this managed control centrally and using EventBridge with Amazon SNS to send notifications avoids maintaining custom rule code, Lambda functions, scheduled scans, and per-account operational components.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!