| If the application owner and Authorizing Official have determined that encryption of data at rest is NOT required, this is not a finding. |
Verify the operating system implements encryption to protect the confidentiality and integrity of information at rest.
If a disk or filesystem requires encryption, ask the system owner, DBA, and SA to demonstrate the use of filesystem and/or disk-level encryption. If this is required and is not found, this is a finding.
To check if full disk encryption is enabled, log in to RHEL as an admin user and run the following commands:
Identify the partition that Redis Enterprise is located on.
# blkid /dev/[name of partition]
If the output shows TYPE="crypto_LUKS" then the partition is encrypted.
If encryption must be used and is not employed, this is a finding.