AWS Redshift Terraform module
Upstream version 7.1.1
8 controls from NYDFS Cybersecurity Regulation requirements
Terraform Module Source
nydfs23.compliance.tf/terraform-aws-modules/redshift/awsCloudWatch log groups should have retention period of at least 365 days
cloudwatch_log_group_retention_period_365500.14(a)
Framework requirement
Log groups should have encryption at rest enabled
log_group_encryption_at_rest_enabled500.15(a)
Framework requirement
Redshift clusters should have audit logging enabled
redshift_cluster_audit_logging_enabled500.14(a)
Framework requirement
Redshift clusters should have automatic snapshots enabled
redshift_cluster_automatic_snapshots_min_7_days500.02(b)(5)
Framework requirement
Redshift cluster encryption in transit should be enabled
redshift_cluster_encryption_in_transit_enabled500.15(a)
Framework requirement
Redshift clusters should have KMS encryption enabled
redshift_cluster_kms_enabled500.15(a)
Framework requirement
Redshift clusters should prohibit public access
redshift_cluster_prohibit_public_access500.07
Framework requirement
VPC Security groups should only allow unrestricted incoming traffic for authorized ports
vpc_security_group_allows_ingress_authorized_ports500.02(b)(2)
Framework requirement