Amazon RDS instance inventory

Track relational-database ownership and protection requirements.

Description

AWS::RDS::DBInstance declares a managed relational-database instance. Its presence is asset information; using a database is not itself a vulnerability.

Potential impact

An omitted database can be missed during access, backup, and recovery-plan reviews.

Remediation

Record the instance’s owner and data purpose, and check storage encryption, backups, deletion protection, and access permissions.

Examples

These excerpts omit other required settings and select storage encryption for a new instance of the same engine. This cannot be applied directly to an existing unencrypted instance; a separate migration, such as restoring an encrypted snapshot copy, is required.

Before

json
{
  "Resources": {
    "DBInstanceSample1": {
      "Type": "AWS::RDS::DBInstance",
      "Properties": {
        "Engine": "oracle-ee",
        "StorageEncrypted": false
      }
    }
  }
}

After

json
{
  "Resources": {
    "DBInstanceSample1": {
      "Type": "AWS::RDS::DBInstance",
      "Properties": {
        "Engine": "oracle-ee",
        "StorageEncrypted": true
      }
    }
  }
}

References