Control: AWS Redshift clusters should be encrypted with KMS
Description
Ensure that AWS Redshift clusters are using a specified AWS Key Management Service (AWS KMS) key for encryption. The rule is compliant if encryption is enabled and the cluster is encrypted with the key provided in the kmsKeyArn parameter. The rule is non-compliant if the cluster is not encrypted or encrypted with another key.
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.redshift_cluster_kms_enabledSnapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.redshift_cluster_kms_enabled --shareSQL
This control uses a named query:
select  arn as resource,  case    when encrypted and kms_key_id is not null then 'ok'    else 'alarm'  end as status,  case    when encrypted and kms_key_id is not null then title || ' encrypted with KMS.'    else title || ' not encrypted with KMS'  end as reason    , region, account_idfrom  aws_redshift_cluster;