Aqua CSPM

RDS Automated Backups

Quick Info

Plugin TitleRDS Automated Backups
CloudAWS
CategoryRDS
DescriptionEnsures automated backups are enabled for RDS instances
More InfoAWS provides a simple method of backing up RDS instances at a regular interval. This should be enabled to provide an option for restoring data in the event of a database compromise or hardware failure.
AWS Linkhttp://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_WorkingWithAutomatedBackups.html
Recommended ActionEnable automated backups for the RDS instance

Detailed Remediation Steps

  1. Log into the AWS Management Console.
  2. Select the “Services” option and search for RDS.
  3. Scroll down the left navigation panel and choose “Databases”.
  4. Select the “Database” that needs to be verified and click on the selected “Databse” from the “DB identifier” column to access the database.
  5. Click on the “Maintenance & backups” under the selected database configuration page.
  6. Scroll down the “Maintenance & backups” tab and check the “Backup”.Check the “Automated backups” and if “Disabled " is showing than automated backups are not enabled for selected RDS instances.
  7. Repeat steps number 2 - 6 to check other RDS instances.
  8. Select the “Database” on which automated backup needs to be enabled. Click the “Modify” button at the top to make the necessary changes.
  9. Scroll down the “Modify DB Instance” page and check for “Backup” section.
  10. On the “Backup” section under “Backup retention period” select number of days between 1 to 35. Select the “Start Time” during which the automated backups are created.
  11. Scroll down the “Modify DB Instance” page and click on “Continue” button.
  12. On the “Scheduling of modifications” choose “Apply immediately” so that it will made the above changes applied as soon as possible and click on the “Modify DB Instance” button.
  13. Once the automated backups are enabled,the Automated Backups status should change to “Enabled”.
  14. Repeat steps number 8 - 13 to enable automated backups for other RDS Instances.