AWS Redshift Terraform module
Upstream version 7.1.1
9 controls from NIST Cybersecurity Framework v2.0 requirements
Terraform Module Source
nistcsf.compliance.tf/terraform-aws-modules/redshift/awsCloudWatch log groups should have retention period of at least 365 days
cloudwatch_log_group_retention_period_365RC.RP-06
Framework requirement
Log groups should have encryption at rest enabled
log_group_encryption_at_rest_enabledPR.DS-1
Framework requirement
Redshift clusters should have automatic snapshots enabled
redshift_cluster_automatic_snapshots_min_7_daysPR.IR-03
Framework requirement
Redshift clusters should have automatic upgrades to major versions enabled
redshift_cluster_automatic_upgrade_major_versions_enabledPR.PS-02
Framework requirement
Redshift cluster encryption in transit should be enabled
redshift_cluster_encryption_in_transit_enabledPR.DS-02
Framework requirement
Redshift clusters should have enhanced VPC routing enabled
redshift_cluster_enhanced_vpc_routing_enabledPR.IR-04
Framework requirement
Redshift clusters should have KMS encryption enabled
redshift_cluster_kms_enabledID.BE-5
Framework requirement
Redshift clusters should have Multi-AZ deployments enabled
redshift_cluster_multiple_az_enabledPR.DS-4
Framework requirement
Redshift clusters should prohibit public access
redshift_cluster_prohibit_public_accessPR.AC-3
Framework requirement