Low
Backup
Regional
AWS Backup recovery points should be tagged
Description
Flags AWS Backup recovery points that have no user-defined tags. Tags help associate recovery points with the owning team, environment, and retention policy; untagged recovery points are operationally opaque. Note: this evaluator inspects the most recent recovery point per protected resource (matching the scope of the existing Backup recovery-point collection).
Remediation
Apply at least one user-defined tag to every AWS Backup recovery point.
Steps
- Open the AWS Backup console and choose Backup vaults, then the affected vault.
- Select the recovery point.
- Choose Manage tags and add at least one tag with a non-aws: prefixed key (e.g. Owner, Environment).
- Save the changes.