Data protection

OpenSearch (Elasticsearch) node to node encryption disabled

Platform(s)
Compliance Frameworks

AWS Foundational Security Best Practices Controls, CCPA, CPRA, iso_27001_2022, iso_27002_2022, Mitre ATT&CK, NIST 800-171, NIST 800-53, Orca Best Practices, PDPA, UK Cyber Essentials

Description

It was found that OpenSearch (Elasticsearch) is not using node to node encryption. There is a risk for data leakage when traffic is not encrypted.