Amazon Neptune
š Unencrypted database poses a threat to data confidentiality and integrity, making encryption imperative to maintain a secure database environment.
- Section: Encryption
- Severity: High
- CWE: CWE-311 Missing Encryption of Sensitive Data
- Assurance Scope: PCI, NIST, GDPR, HIPPA
- Threat Modeling Principal: Tampering, Information Disclosure
- Rule Set: Threat Modeling - Cloud Configuration Check
š Encryption using the Customer Master Key (CMK) provides a tailored and robust layer of security and is required for some high security environments.
- Section: Encryption
- Severity: High
- CWE: CWE-653 Insufficient Compartmentalization
- Assurance Scope: PCI, NIST, GDPR, HIPPA
- Threat Modeling Principal: Tampering, Information Disclosure
- Rule Set: Threat Modeling - Cloud Configuration Check
Updated 11 months ago
Whatās Next