Ensure that RDS DB instances are not publicly accessible.
Enabling public access increase chances of data insecurity. Public access should always be disabled and only know IP addresses should be whitelisted.
Modify security settings for RDS DB instances to disable the public access.