More Info:

Field-level encryption should be enabled for your Amazon CloudFront web distributions in order to help protect sensitive data like credit card numbers or social security numbers, and to help protect your data across application services.

Risk Level

Medium

Address

Security

Compliance Standards

SOC2, GDPR, ISO27001, HIPAA, HITRUST, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “CloudFront Distributions Should Have Field-Level Encryption Enabled” in AWS using AWS console, follow the below steps:

  1. Login to AWS Management Console.
  2. Go to the CloudFront service.
  3. Select the CloudFront distribution for which you want to enable field-level encryption.
  4. Click on the “Edit” button in the top menu.
  5. Scroll down to the “Security and Privacy” section.
  6. In the “Field-level Encryption Config” section, click on the “Create Field-level Encryption Config” button.
  7. In the “Create Field-level Encryption Config” dialog box, enter a name for the configuration and click on the “Create” button.
  8. In the “Field-level Encryption Config” section, select the newly created configuration from the dropdown list.
  9. Click on the “Yes, Edit” button to save the changes.
  10. Finally, click on the “Save Changes” button to complete the remediation.

By following these steps, you have successfully enabled Field-level Encryption for the selected CloudFront distribution in AWS.

Additional Reading: