Amazon DynamoDB table inventory

Track DynamoDB table ownership and protection requirements.

Description

AWS::DynamoDB::Table declares a managed NoSQL database table. This is an asset-inventory item; using a table alone does not require changing or removing it.

Potential impact

An omitted table can become a gap in access, backup, and cost management.

Remediation

Include the table in the inventory and check access policies, encryption-key selection, backups, and point-in-time recovery requirements.

Examples

Both configurations encrypt stored data. Omitting SSEEnabled uses an AWS owned key; setting it to true here selects an AWS managed key, for which KMS charges can apply.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  DynamoDBOnDemandTable:
    Type: AWS::DynamoDB::Table
    Properties:
      TableName: test
      AttributeDefinitions:
        - AttributeName: pk
          AttributeType: S
      KeySchema:
        - AttributeName: pk
          KeyType: HASH
      BillingMode: PAY_PER_REQUEST

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  DynamoDBOnDemandTable:
    Type: AWS::DynamoDB::Table
    Properties:
      TableName: test
      AttributeDefinitions:
        - AttributeName: pk
          AttributeType: S
      KeySchema:
        - AttributeName: pk
          KeyType: HASH
      BillingMode: PAY_PER_REQUEST
      SSESpecification:
        SSEEnabled: true

References