Low Backup Regional

AWS Backup recovery points should be tagged

Description

Flags AWS Backup recovery points that have no user-defined tags. Tags help associate recovery points with the owning team, environment, and retention policy; untagged recovery points are operationally opaque. Note: this evaluator inspects the most recent recovery point per protected resource (matching the scope of the existing Backup recovery-point collection).


Remediation

Apply at least one user-defined tag to every AWS Backup recovery point.

Steps

  1. Open the AWS Backup console and choose Backup vaults, then the affected vault.
  2. Select the recovery point.
  3. Choose Manage tags and add at least one tag with a non-aws: prefixed key (e.g. Owner, Environment).
  4. Save the changes.