Ensure that your Amazon Aurora database clusters make use of Copy Tags to Snapshots feature in order to allow tags set on your Aurora database clusters to be automatically copied to any automated or manual snapshots that are created from these clusters. Once the feature is enabled, tags can be copied to all future copies of an Amazon Aurora snapshots, including cross-region snapshots.
This rule resolution is part of the Cloud Conformity Security & Compliance tool for AWS
excellence
Copying your Amazon RDS Aurora cluster tags to any automated or manual snapshots taken from your database clusters allows you to easily set metadata (including access policies) on your snapshots in order to match the parent clusters.
Audit
To determine if your Amazon Aurora clusters have Copy Tags to Snapshots feature enabled, perform the following operations:
Remediation / Resolution
To enable Copy Tags to Snapshots feature for your existing Amazon Aurora database clusters, perform the following operations:
References
- AWS Documentation
- General
- Tagging Amazon RDS resources
- Modifying an Amazon Aurora DB cluster
- AWS Command Line Interface (CLI) Documentation
- rds
- describe-db-clusters
- modify-db-cluster
Unlock the Remediation Steps
Gain free unlimited access
to our full Knowledge Base
Over 750 rules & best practices
for and
Get started for FREE
You are auditing:
Enable Aurora Cluster Copy Tags to Snapshots
Risk level: High