All challenges

Encrypt everything (rest & transit)

intermediate
Scenario & brief

A compliance review requires encryption at rest and in transit across the board. Today the load balancer serves plain HTTP, and the database, cache, and object store keep data in the clear.

Turn on encryption everywhere:

  • TLS in transit at the load balancer, app, and database, and
  • encryption at rest for the database, cache, and S3 bucket.
2,000 rps peakp99 ≤ 200ms99.9% availdurability: criticalbudget $200/mo

Load Balancer

Networking

System health

Erupting · SLA breach

0

/ 100

Score

SLA not met yet

Monthly cost

$22

Budget $200/mo · within budget

Metrics

Security posture0
Connectivity100
Requirements met0

Requirements

  • Load balancer serves TLS/HTTPS cleartext (need encrypted in transit)
  • App traffic encrypted in transit cleartext (need encrypted in transit)
  • Database connections use TLS cleartext (need encrypted in transit)
  • Database encrypted at rest plaintext (need encrypted at rest)
  • Cache encrypted at rest plaintext (need encrypted at rest)
  • S3 bucket encrypted at rest plaintext (need encrypted at rest)

Advisor

  • Load balancer serves TLS/HTTPS: Require TLS/HTTPS in transit.
  • App traffic encrypted in transit: Require TLS/HTTPS in transit.
  • Database connections use TLS: Require TLS/HTTPS in transit.
  • Database encrypted at rest: Enable encryption at rest.
  • Cache encrypted at rest: Enable encryption at rest.
  • S3 bucket encrypted at rest: Enable encryption at rest.

Discussion

Sign in to join the discussion.

No comments yet. Be the first to start the discussion.

For learning purposes only. Costs and capacities are illustrative, not live AWS prices. Not affiliated with or endorsed by Amazon Web Services.