Description
A DynamoDB table inventory helps identify the purpose and ownership of data stores. This is asset-management information; the presence of a table is not itself a vulnerability.
Potential impact
Tables omitted from the inventory may also be missed during access, backup, and encryption-key reviews.
Remediation
Record each table’s service and owner, then review access policies, point-in-time recovery (PITR), and encryption-key settings.
Examples
The examples add service and environment tags without editing access-policy or backup configuration. Also check the effect of any tag-based IAM policies.
Before
hcl
resource "aws_dynamodb_table" "orders" {
name = "orders"
billing_mode = "PAY_PER_REQUEST"
hash_key = "id"
attribute {
name = "id"
type = "S"
}
}
After
hcl
resource "aws_dynamodb_table" "orders" {
name = "orders"
billing_mode = "PAY_PER_REQUEST"
hash_key = "id"
attribute {
name = "id"
type = "S"
}
tags = {
Service = "orders"
Environment = "production"
}
}