Your Amazon Aurora MySQL database clusters have the Backtrack feature enabled. Backtrack lets you quickly…
Your Amazon RDS DB clusters are configured to automatically copy tags to their snapshots. When enabled…
Amazon RDS event notification subscriptions are configured for database cluster events, specifically…
Your Amazon RDS database clusters are not using default master usernames like admin or postgres. Using…
Amazon RDS DB clusters have deletion protection enabled. When enabled, this feature prevents accidental or…
Your Amazon RDS database clusters have IAM database authentication enabled. With IAM authentication, you…
Your Amazon RDS clusters (Aurora MySQL, Aurora PostgreSQL, MySQL, PostgreSQL) export database logs to…
Your Amazon RDS clusters have automatic minor version upgrades enabled. When enabled, AWS automatically…
Your Amazon RDS DB clusters are deployed in a Multi-AZ (Multi-Availability Zone) configuration. Multi-AZ…
Your Amazon RDS database clusters use non-default ports instead of well-known defaults. Default ports include:
Your Amazon RDS database clusters are protected by an AWS Backup plan. AWS Backup provides centralized…
Your Amazon RDS clusters (Aurora and Multi-AZ DB clusters) have storage encryption enabled. Encryption at…
Your Amazon RDS database instances have automated backups turned on. When backups are enabled, AWS…
SSL/TLS certificates on your Amazon RDS database instances are valid and not approaching expiration…
Your RDS database instances are configured to automatically copy tags to snapshots. When enabled, any tags…
Amazon RDS event notification subscriptions are configured to capture critical database instance events…
Your Amazon RDS database instances use a custom master username instead of common defaults like admin…
Deletion protection is enabled on your Amazon RDS database instances. When enabled, deletion protection…
Your Amazon RDS database instances are running on supported, non-deprecated engine versions for MySQL…
Amazon RDS database instances have Enhanced Monitoring enabled. Enhanced Monitoring provides real-time…
You have set up notifications for changes to your RDS parameter groups. Parameter groups control important…
You have an RDS event subscription configured to monitor database security group events. When enabled, AWS…
Your Amazon RDS database instances have IAM database authentication enabled. IAM authentication lets you…
Your Amazon RDS database instances are deployed within a Virtual Private Cloud (VPC). A VPC provides…
Your Amazon RDS database instances are configured to export logs to CloudWatch Logs. When enabled…
Amazon RDS database instances have automatic minor version upgrades enabled. When enabled, AWS…
Your Amazon RDS database instances have Multi-AZ (Multi-Availability Zone) deployment enabled. Multi-AZ…
Your Amazon RDS database instances are not exposed to the public internet. It examines three factors:
Your Amazon RDS database instances use non-default ports. Default ports are well-known (e.g., MySQL uses…
Your Amazon RDS database instances are included in an AWS Backup plan. AWS Backup provides centralized…
Your Amazon RDS database instances have storage encryption enabled at rest. When encryption is turned on…
Your Amazon RDS database instances enforce SSL/TLS encryption for all client connections. When enabled…
Your Amazon RDS database snapshots (both DB instance snapshots and Aurora cluster snapshots) are encrypted…
Amazon RDS database snapshots (both DB snapshots and DB cluster snapshots) that are publicly accessible. A…