Ensure that Amazon RDS event notification subscriptions are enabled for database instance level events. Amazon RDS groups these events into categories that you can subscribe to so that you can be notified when an event in that category occurs. You can subscribe to an event category for a database instance, database snapshot, database parameter group, etc. For example, if you subscribe to the "Backup" category for a given database instance, you will be notified whenever a backup-related event occurs that affects the RDS database instance.
This rule can help you with the following compliance standards:
This rule resolution is part of the Cloud Conformity Security & Compliance tool for AWS
efficiency
excellence
Amazon RDS event subscriptions for instance level events are designed to provide incident notification of event changes triggered at the database engine level such as failure, failover, low storage, maintenance, recovery or deletion.
Audit
To determine if there are any RDS event subscriptions enabled for instance level events, available in your AWS account, perform the following:
Remediation / Resolution
To enable subscriptions to the Amazon RDS event notifications for instance level events, perform the following actions:
References
- AWS Documentation
- Amazon RDS FAQs
- Using Amazon RDS Event Notification
- Create a Topic
- Subscribe to a Topic
- CIS Amazon Web Services Foundations
- AWS Command Line Interface (CLI) Documentation
- rds
- describe-event-subscriptions
- create-event-subscription
- sns
- create-topic
- subscribe
- confirm-subscription
Unlock the Remediation Steps
Gain free unlimited access
to our full Knowledge Base
Over 750 rules & best practices
for and
Get started for FREE
You are auditing:
Instance Level Events Subscriptions
Risk level: Low