Encryption & Access Control
AWS KMS managed encryption keys
No application changes required
Must enable during database creation
Data, backups, snapshots, logs, replicas
AWS-provided certificates for all engines
Parameter groups enforce SSL usage
Automatic certificate management
Client-side SSL configuration required
Force SSL with parameter groups
Enhanced SSL security options
Native SSL/TLS support
Uses IAM credentials instead
15-minute token lifetime
Access control through IAM
Firewall rules at instance level
Multi-AZ private subnet placement
Recommended for database isolation
At rest and in transit
Database isolation
When possible
Credential management
SOC, PCI DSS, HIPAA, FedRAMP
Database-specific audit logs
API call logging and monitoring
Query-level performance monitoring
Real-time OS metrics
Custom dashboards and alerts