Data protection

Elasticsearch using default KMS keys

Risk Level

Informational (4)

Compliance Frameworks


It was found that Elasticsearch DB {AwsElasticSearch} using default KMS keys. AWS uses KMS key to encrypt resource. When another key has not been supplied, it uses the default key.
  • Recommended Mitigation

    It is recommended to use customer managed keys instead of default KMS keys.