Q: A compliance standard requires that all data at rest in your RDS databases be encrypted. How does AWS RDS encryption work, and what is transparent data encryption (TDE)?
AWS RDS "Encryption at Rest" utilizes AWS KMS (Key Management Service). It operates at the underlying storage volume (EBS) level. When da...
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
AWS RDS "Encryption at Rest" utilizes AWS KMS (Key Management Service). It operates at the underlying storage volume (EBS) level. When data is written to the disk, the hypervisor encrypts it; when read, it decrypts it. This protects against someone physically stealing the hard drive or gaining access to the raw EBS snapshots. However, any user with SQL access to the database queries the data in plaintext. TDE (Transparent Data Encryption), offered by engines like SQL Server and Oracle, encrypts the data at the database page/file level *before* it hits the disk. For true end-to-end security involving PII, you must combine disk-level KMS with application-level or field-level encryption, where the application itself encrypts the SSN or credit card before inserting it, so even DB admins cannot run a SELECT * and see the plaintext.
- Immediate Triage: AWS RDS "Encryption at Rest" utilizes AWS KMS (Key Management Service). It operates at the unde
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.