Enable encryption at rest for Amazon Timestream to protect your data while it is stored. Utilize AWS Key Management Service (KMS) to manage and control the encryption keys used for data encryption. Configure Timestream to encrypt your data using AWS-managed keys or customer-managed keys.
Rationale
This helps ensure that the data is kept secure and protected when at rest. The user must choose from two key options which then determine when the data is encrypted at rest.
Impact
Encryption at rest ensures that Timestream data remains protected even if the underlying storage media is compromised.
Audit Procedure
Using AWS Console
Understand Encryption at Rest in Timestream:
Familiarize yourself with the concept of encryption at rest and its importance in securing your data in Timestream. Understand that encryption at rest ensures that your data remains protected even if the underlying storage media is compromised.
Create an AWS Key Management Service (KMS) Key:
Open the AWS Management Console and navigate to the AWS Key Management Service (KMS) service. Create a new KMS customer master key (CMK) or use an existing one to manage the encryption keys for Timestream. Follow the AWS documentation and best practices for creating and managing KMS keys.
Enable Encryption at Rest in Timestream:
Open the Amazon Timestream console. Select the Timestream database or table you want to enable encryption at rest. Click on the "Encryption" tab or section. Choose the option to enable encryption at rest. Select the KMS key that you created earlier to be used for encryption.
Verify Encryption at Rest:
Confirm that encryption at rest is enabled for the selected Timestream database or table. Review the encryption settings in the Timestream console to ensure the correct KMS key is associated.
Monitor and Audit Encryption at Rest:
Regularly monitor the encryption at rest status in the Timestream console. Leverage AWS CloudTrail and AWS CloudWatch to monitor and track encryption-related activities or events. Set up appropriate alerts and notifications to detect any issues or unauthorized changes to the encryption settings.
Test Data Access and Decryption:
Access the Timestream data that is encrypted at rest. Verify that you can retrieve and decrypt the data using the appropriate access controls and KMS key permissions. Perform thorough testing to ensure data access and decryption functions as expected.
Review and Update Encryption Configuration:
Regularly review your encryption configuration and settings for Timestream. Ensure that the appropriate KMS key is still associated with the Timestream resources. Update the encryption settings if necessary, such as rotating encryption keys or modifying key policies.
Expected Result
Encryption at rest should be enabled for all Timestream databases and tables using either AWS-managed or customer-managed KMS keys.
Remediation
Using AWS Console
Follow the audit steps above to enable encryption at rest for your Amazon Timestream resources.
Default Value
Amazon Timestream encrypts all data at rest by default using AWS-managed keys. Customer-managed KMS keys can be configured for additional control.
1---2name: cis-aws-database-10-23description: Ensure Data at Rest is Encrypted4---56# 10.2 Ensure Data at Rest is Encrypted (Manual)78## Description910Enable encryption at rest for Amazon Timestream to protect your data while it is stored. Utilize AWS Key Management Service (KMS) to manage and control the encryption keys used for data encryption. Configure Timestream to encrypt your data using AWS-managed keys or customer-managed keys.1112## Rationale1314This helps ensure that the data is kept secure and protected when at rest. The user must choose from two key options which then determine when the data is encrypted at rest.1516## Impact1718Encryption at rest ensures that Timestream data remains protected even if the underlying storage media is compromised.1920## Audit Procedure2122### Using AWS Console23241. Understand Encryption at Rest in Timestream:25 - Familiarize yourself with the concept of encryption at rest and its importance in securing your data in Timestream. Understand that encryption at rest ensures that your data remains protected even if the underlying storage media is compromised.262. Create an AWS Key Management Service (KMS) Key:27 - Open the AWS Management Console and navigate to the AWS Key Management Service (KMS) service. Create a new KMS customer master key (CMK) or use an existing one to manage the encryption keys for Timestream. Follow the AWS documentation and best practices for creating and managing KMS keys.283. Enable Encryption at Rest in Timestream:29 - Open the Amazon Timestream console. Select the Timestream database or table you want to enable encryption at rest. Click on the "Encryption" tab or section. Choose the option to enable encryption at rest. Select the KMS key that you created earlier to be used for encryption.304. Verify Encryption at Rest:31 - Confirm that encryption at rest is enabled for the selected Timestream database or table. Review the encryption settings in the Timestream console to ensure the correct KMS key is associated.325. Monitor and Audit Encryption at Rest:33 - Regularly monitor the encryption at rest status in the Timestream console. Leverage AWS CloudTrail and AWS CloudWatch to monitor and track encryption-related activities or events. Set up appropriate alerts and notifications to detect any issues or unauthorized changes to the encryption settings.346. Test Data Access and Decryption:35 - Access the Timestream data that is encrypted at rest. Verify that you can retrieve and decrypt the data using the appropriate access controls and KMS key permissions. Perform thorough testing to ensure data access and decryption functions as expected.367. Review and Update Encryption Configuration:37 - Regularly review your encryption configuration and settings for Timestream. Ensure that the appropriate KMS key is still associated with the Timestream resources. Update the encryption settings if necessary, such as rotating encryption keys or modifying key policies.3839## Expected Result4041Encryption at rest should be enabled for all Timestream databases and tables using either AWS-managed or customer-managed KMS keys.4243## Remediation4445### Using AWS Console4647Follow the audit steps above to enable encryption at rest for your Amazon Timestream resources.4849## Default Value5051Amazon Timestream encrypts all data at rest by default using AWS-managed keys. Customer-managed KMS keys can be configured for additional control.5253## References54551. https://aws.amazon.com/products/databases/5657## CIS Controls5859| Controls Version | Control | IG 1 | IG 2 | IG 3 |60| ---------------- | ------------------------------------------ | ---- | ---- | ---- |61| v8 | 3.11 Encrypt Sensitive Data at Rest | | x | x |62| v7 | 14.8 Encrypt Sensitive Information at Rest | | | x |6364## Profile6566Level 1 | Manual
Run npx skillmds@latest add cyberstrikeus/cis-aws-database-10-2 in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Ensure Data at Rest is Encrypted It is listed under DevOps & Infra on SkillMD.
SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
cyberstrikeus (@cyberstrikeus) published this skill. Their other Agent Skills are listed on their SkillMD profile.