Ensure that your Amazon Database Migration Service (DMS) replication instances have the Auto Minor Version Upgrade feature enabled in order to receive automatically minor engine upgrades. The automatic upgrades are applied to DMS replication instances during system maintenance window, defined by the day of the week, the time of day, and the time zone (UTC by default). Each minor version upgrade is fully available only after it is approved by Amazon Web Services.
This rule can help you with the following compliance standards:
- APRA
- MAS
- NIST4
For further details on compliance standards supported by Conformity, see here.
This rule resolution is part of the Conformity Security & Compliance tool for AWS.
Amazon Database Migration Service is a managed web service that you can use to migrate data from a source database to a target database. An AWS DMS replication instance initiates the connection between the two data stores, transfers the data and caches any changes that occur on the source data store at the initial data load. The DMS service releases engine version upgrades regularly to introduce new software features, bug fixes, security patches and performance improvements.
Audit
To determine if your AWS DMS replication instances have Auto Minor Version Upgrade feature enabled, perform the following actions:
Remediation / Resolution
To update your Amazon DMS replication instances configuration in order to enable Auto Minor Version Upgrade, perform the following actions:
References
- AWS Documentation
- AWS Database Migration Service FAQs
- How AWS Database Migration Service Works
- Working with an AWS DMS Replication Instance
- AWS Command Line Interface (CLI) Documentation
- dms
- describe-replication-instances
- modify-replication-instance
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
DMS Auto Minor Version Upgrade
Risk Level: Medium