AWS OpenSearch Terraform module

Upstream version 2.11.1
8 controls from NYDFS Cybersecurity Regulation requirements

Terraform Module Source

nydfs23.compliance.tf/terraform-aws-modules/opensearch/aws
CloudWatch log groups should have retention period of at least 365 days
cloudwatch_log_group_retention_period_365500.14(a)
Framework requirement
Log groups should have encryption at rest enabled
log_group_encryption_at_rest_enabled500.15(a)
Framework requirement
OpenSearch domains should have audit logging enabled
opensearch_domain_audit_logging_enabled500.14(a)
Framework requirement
OpenSearch domains should have encryption at rest enabled
opensearch_domain_encryption_at_rest_enabled500.15(a)
Framework requirement
OpenSearch domains should be in a VPC
opensearch_domain_in_vpc500.07
Framework requirement
OpenSearch domains should have logging to CloudWatch Logs enabled
opensearch_domain_logs_to_cloudwatch500.14(a)
Framework requirement
OpenSearch domains node-to-node encryption should be enabled
opensearch_domain_node_to_node_encryption_enabled500.15(a)
Framework requirement
VPC Security groups should only allow unrestricted incoming traffic for authorized ports
vpc_security_group_allows_ingress_authorized_ports500.02(b)(2)
Framework requirement