Ensure that your Amazon RDS database instances have set a minimum backup retention period in order to achieve compliance requirements. Trend Micro Cloud One™ – Conformity recommends a minimum (default) retention period of 7 (seven) days but you can adjust the minimumRetentionPeriod parameter value to narrow or extend the default retention period (Amazon RDS allows a maximum retention period of 35 days).
This rule can help you with the following compliance standards:
- NIST4
For further details on compliance standards supported by Conformity, see here.
This rule can help you work with the AWS Well-Architected Framework.
This rule resolution is part of the Conformity Security & Compliance tool for AWS.
Having a minimum retention period set for your database instances will enforce your backup strategy to follow best practices as specified in the compliance regulations. Retaining point-in-time database snapshots for a longer period of time will allow you to handle more efficiently your data restoration process in the event of failure.
Note: This guide will use 7 days (recommended) as the threshold for the minimum backup retention period. However, you can adjust anytime the number of days to suit your requirements.
Audit
To determine if your Amazon RDS database instances have a sufficient backup retention period configured for automated backups, perform the following actions:
Remediation / Resolution
To update your Amazon RDS database instance backup configuration in order to extend the backup retention period for compliance, perform the following actions:
References
- AWS Documentation
- Amazon RDS FAQs
- Managing an Amazon RDS DB instance
- Backing up and restoring an Amazon RDS DB instance
- Working with backups
- Modifying an Amazon RDS DB instance
- AWS Command Line Interface (CLI) Documentation
- rds
- describe-db-instances
- modify-db-instance
- CloudFormation Documentation
- Amazon Relational Database Service resource type reference
- Terraform Documentation
- AWS Provider
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
RDS Sufficient Backup Retention Period
Risk Level: Medium