Decommission Data and Media Securely

Information

When you ask AWS to delete data in the cloud, AWS does not decommission the underlying physical media; instead, the storage blocks are marked as unallocated.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

When you have regulatory or business reasons to require further controls for securely decommissioning data, you can implement data encryption at rest using customer managed keys, which are not stored in the cloud. You would delete the key used to protect the decommissioned data, making it irrecoverable.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: MEDIA PROTECTION, PHYSICAL AND ENVIRONMENTAL PROTECTION

References: 800-53|MP-6, 800-53|PE-1

Plugin: amazon_aws

Control ID: 3ec7dcb4689a71d88745dd4401d4d2348ea7da9abe7cb7218a203535da2f362c