---
title: Keyspaces tables should use KMS encryption
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Keyspaces tables should use KMS
  encryption
---

# Keyspaces tables should use KMS encryption
 
## Description{% #description %}

Amazon Keyspaces tables should have encryption at rest enabled to protect stored data and meet compliance requirements for managed Cassandra workloads. AWS owned keys (the default), AWS managed KMS keys, and customer managed KMS keys are all acceptable. This rule verifies that encryption at rest is not explicitly disabled.

## Remediation{% #remediation %}

Ensure encryption at rest is enabled on the table. AWS owned keys, AWS managed KMS keys, and customer managed KMS keys are all acceptable. For guidance, see [Encryption at rest for Amazon Keyspaces](https://docs.aws.amazon.com/keyspaces/latest/devguide/encryption.howitworks.html).
