Skip to main content

MongoDB Instance Uses Custom Key for TDE

ID: rule:aliyun:mongodb-instance-encryption-byok-check
Severity: medium

Description

Ensures MongoDB instances use custom KMS keys for Transparent Data Encryption (TDE).

Reason for Violation

Using customer-managed keys for TDE provides better control over encryption and enhances data security.

Recommendation

Enable TDE with a custom KMS key for the MongoDB instance.

Resource Types

  • ALIYUN::MONGODB::Instance