Documentation
README
11.1 Ensure customer-managed keys are used to encrypt AWS Fargate ephemeral storage data for Amazon ECS (Automated)
Description
Use customer-managed AWS KMS keys to encrypt AWS Fargate ephemeral storage data for on Amazon ECS, ensuring that sensitive data remains protected during task execution.
Rationale
Customer-managed KMS keys offer enhanced control over encryption, including key rotation, access policies, and audit trails.
Impact
There are costs and configuration overhead associated with setting up and managing customer-managed keys.
Audit Procedure
Using AWS Console
- Login to the ECS console using https://console.aws.amazon.com/ecs/.
- In the left panel, click
Clusters. - Click the name of a cluster.
- Ensure that
Fargate ephemeral storageis not set to-. - Repeat steps 1-4 for each ECS cluster.
Using AWS CLI
Run the following command to list clusters:
aws ecs list-clusters
Run the following command to view the Fargate ephemeral storage KMS key ID configured for a cluster:
aws ecs describe-clusters --clusters <cluster-arn> --include CONFIGURATIONS --query 'clusters[*].configuration.managedStorageConfiguration.fargateEphemeralStorageKmsKeyId'
Ensure the command returns a customer-managed KMS key ARN. Repeat for each cluster.
Expected Result
Each ECS cluster returns a valid customer-managed KMS key ARN for the Fargate ephemeral storage configuration, rather than - or empty.
Remediation
Using AWS Console
- Login to the ECS console using https://console.aws.amazon.com/ecs/.
- In the left panel, click
Clusters. - Click the name of a cluster.
- Click
Update cluster. - Expand the
Encryptionsection. - Under
Fargate ephemeral storage, select a customer-managed KMS key. Note: Ensure the KMS key has appropriate Fargate service permissions. - Click
Update. - Repeat steps 1-7 for each ECS cluster requiring remediation.
Using AWS CLI
N/A - Remediation is console-based for this control.
Default Value
AWS Fargate ephemeral storage data is encrypted by default.
References
- https://docs.aws.amazon.com/AmazonECS/latest/developerguide/fargate-storage-encryption.html
- https://docs.aws.amazon.com/AmazonECS/latest/developerguide/fargate-create-storage-key.html
- https://awscli.amazonaws.com/v2/documentation/api/2.0.33/reference/ecs/list-clusters.html
- https://awscli.amazonaws.com/v2/documentation/api/2.0.33/reference/ecs/describe-clusters.html
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 3.11 Encrypt Sensitive Data at Rest | X | X | |
| v7 | 14.8 Encrypt Sensitive Information at Rest | X |
Profile
Level 2 | Automated