---
title: Redshift Serverless namespaces should use KMS encryption
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Redshift Serverless namespaces should
  use KMS encryption
---

# Redshift Serverless namespaces should use KMS encryption
 
## Description{% #description %}

Redshift Serverless namespaces should have encryption at rest enabled to protect stored data and snapshots. AWS owned keys (the default), AWS managed KMS keys, and customer managed KMS keys are all acceptable. This rule verifies that encryption at rest is not explicitly disabled.

## Remediation{% #remediation %}

Ensure encryption at rest is configured for the namespace. AWS owned keys, AWS managed KMS keys, and customer managed KMS keys are all acceptable. For guidance, see [Data protection in Amazon Redshift Serverless](https://docs.aws.amazon.com/redshift/latest/mgmt/serverless-security.html).
