Skip to main content

Amazon VPC

VPC Encryption Controls

Monitor and Enforce Encryption-in-Transit within and across VPCs in a region

What is VPC Encryption Controls?

VPC Encryption Controls is a security and compliance feature that gives you visibility into the encryption status of your traffic flows and the resources allowing cleartext traffic within your VPC and enables you to authoritatively enforce encryption in transit within and across your VPCs in a region.

VPC Encryption Controls uses both application-layer encryption and built-in encryption in transit capability of AWS nitro system hardware to ensure encryption enforcement. This feature also extends the native hardware-layer encryption beyond the modern Nitro instances to other AWS services including Fargate, Application Load Balancer, Transit Gateways and many others.

VPC Encryption Controls Modes

Monitor Mode: Monitor mode provides visibility into the encryption status of traffic flows between your AWS resources inside and across VPCs in a region. The encryption status of all traffic is monitored and logged using VPC Flow logs.

Enforce Mode: Enforce mode prevents the creation of resources inside the VPC that do not enforce encryption in transit. This applies to creation of older EC2 instances that don’t support native built in encryption. It also applies to internet gateways, virtual private gateways or NAT gateways - these resources help you route your traffic outside AWS boundaries, and you are responsible for ensuring encryption there. To run these services in your encryption-enforced VPCs, you must create resource exclusions (exclusions are only available for certain resource types).

Benefits of Amazon VPC Encryption Controls

  • Monitor the encryption status of VPC traffic flows and track resources allowing plaintext traffic through a single interface.
  • Enable strict encryption requirements within and across VPCs to ensure all traffic is encrypted in transit across services and resources.

  • One Click Setup
  • Enables native encryption transparently on several services
  • Simplifies encryption management across your AWS environment

  • Generate comprehensive audit reports for audits.
  • Detailed logs and reports of encryption status help maintain regulatory compliance standards.

Did you find what you were looking for today?

Let us know so we can improve the quality of the content on our pages