Skip to main content

EMR clusters should be encrypted at rest

SeverityExploitabilityProvidersCategories
HIGHHIGHAWSDATA, PERMISSION

Description

AWS Elastic MapReduce (EMR) is a managed cluster platform that assists running big data frameworks to process and analyze data.

The cluster should always be encrypted at rest to protect the data if accesses are compromised.

Impact

Potential data exposureVisible in logsUser interaction requiredPrivileges required
TrueFalseFalseTrue

Not encrypting storages at rest could lead to data leak in case of an attack.

Remediation guidelines

For AWS EMR version 4.8.0 or later, update the security configuration attached to the EMR cluster so that EncryptionConfiguration.EnableAtRestEncryption is set to true. See this AWS documentation page for configuration examples.

For earlier versions, you will need to manually create a security configuration and then specify your S3 data encryption. The steps are described in the following pages:

Please note that you may encounter service disruption after you reconfigure your cluster as explained in this section

References

How can I help you ?