Encryption at rest can help protect data integrity and can be enabled or disabled when the cluster is provisioned. It is recommended to enable this setting when launching a DocumentDB cluster. For more information, see the AWS documentation.
References:
https://docs.aws.amazon.com/documentdb/latest/developerguide/security.data-protection.html
In AWS Console -
In Terraform -
References:
https://docs.aws.amazon.com/documentdb/latest/developerguide/encryption-at-rest.html
https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/docdb_cluster#kms_key_id