---
title: MemoryDB clusters should use KMS encryption
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > MemoryDB clusters should use KMS
  encryption
---

# MemoryDB clusters should use KMS encryption
 
## Description{% #description %}

MemoryDB clusters should have encryption at rest enabled to protect cached data, backups, and snapshots from unauthorized access. AWS owned keys (the default), AWS managed KMS keys, and customer managed KMS keys are all acceptable. This rule verifies that encryption at rest is not explicitly disabled.

## Remediation{% #remediation %}

Ensure encryption at rest is enabled for the cluster. AWS owned keys, AWS managed KMS keys, and customer managed KMS keys are all acceptable. For guidance, see [Encrypting data at rest in MemoryDB](https://docs.aws.amazon.com/memorydb/latest/devguide/at-rest-encryption.html).
