For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-p3n.md. A documentation index is available at /llms.txt.

Firehose delivery streams should be encrypted at rest

Description

Firehose delivery streams should be encrypted at rest. Server-side encryption protects data via AWS Key Management Service (KMS) before storing data, ensuring sensitive data is not exposed at rest.

Remediation

Enable server-side encryption for your Firehose delivery stream. For more details on data protection in Amazon Data Firehose, see the public documentation