More Info:

This rule checks whether encryption at rest is enabled for the cache of an AWS AppSync API. Enabling encryption at rest helps protect sensitive data stored in the cache from unauthorized access or tampering. It ensures that data is encrypted while stored, providing an additional layer of security.

Risk Level

Medium

Address

Security

Compliance Standards

CBP,SEBI

Triage and Remediation

Check Cause

  1. Sign in to the AWS Management Console.
  2. Navigate to the AppSync service. You can find this by typing ‘AppSync’ into the search bar at the top of the console.
  3. In the AppSync dashboard, select the APIs from the navigation pane.
  4. For each API, click on its name to open its details page. In the details page, click on ‘Settings’ in the left-hand navigation pane.
  5. In the Settings page, look for the ‘Cache’ section. If the ‘Encryption at Rest’ field is set to ‘Disabled’, then Encryption at Rest is not enabled for the App Sync Cache.