Description
AWS::RDS::DBInstance declares a managed relational-database instance. Its presence is asset information; using a database is not itself a vulnerability.
Potential impact
An omitted database can be missed during access, backup, and recovery-plan reviews.
Remediation
Record the instance’s owner and data purpose, and check storage encryption, backups, deletion protection, and access permissions.
Examples
These excerpts omit other required settings and select storage encryption for a new instance of the same engine. This cannot be applied directly to an existing unencrypted instance; a separate migration, such as restoring an encrypted snapshot copy, is required.
Before
json
{
"Resources": {
"DBInstanceSample1": {
"Type": "AWS::RDS::DBInstance",
"Properties": {
"Engine": "oracle-ee",
"StorageEncrypted": false
}
}
}
}
After
json
{
"Resources": {
"DBInstanceSample1": {
"Type": "AWS::RDS::DBInstance",
"Properties": {
"Engine": "oracle-ee",
"StorageEncrypted": true
}
}
}
}