Ensure that Transparent Data Encryption (TDE) is enabled for the supported Alibaba Cloud RDS database instances in order to meet regulatory requirements and prevent unauthorized users from accessing sensitive information.
Transparent Data Encryption (TDE) helps protect sensitive data from unauthorized access by seamlessly encrypting and decrypting database content, backups, and log files during storage operations. The data encryption and decryption process is handled transparently and does not require any additional action from you or your application.
This Knowledge Base (KB) article uses PostgreSQL as an example to show how to verify and enable Transparent Data Encryption (TDE) for RDS database instances. In Alibaba Cloud RDS, TDE is also supported by MySQL and SQL Server instances.
Audit
To determine if Transparent Data Encryption is enabled for supported RDS database instances, perform the following operations:
Remediation / Resolution
To enable Transparent Data Encryption (TDE) for supported Alibaba Cloud RDS database instances, perform the following operations:
References
- Alibaba Cloud Documentation
- Data security and encryption
- Overview
- Configure TDE
- Alibaba Cloud CLI Documentation
- DescribeDBInstances
- DescribeDBInstanceTDE
- ModifyDBInstanceTDE