Medium DMS Regional

DMS endpoints for Neptune databases should have IAM authorization enabled

NIST 800-53PCI DSS v4.0.1PCI DSS v7.3.1

Description

Verifies that AWS DMS endpoints for Neptune databases use IAM authorization, enabling fine-grained access control through a service access role.


Remediation

Enable IAM authorization for your DMS endpoints that connect to Neptune databases to ensure fine-grained access control.

Steps

  1. Navigate to the AWS DMS console
  2. Go to the Endpoints section
  3. Select the Neptune endpoint that needs IAM authorization
  4. Modify the endpoint configuration
  5. In the 'Authentication' section, enable 'IAM database authentication'
  6. Configure the 'Service access role ARN' parameter
  7. Ensure the IAM role has appropriate permissions for Neptune access
  8. Save the configuration changes
  9. Verify that IAM authorization is now enabled for the Neptune endpoint

Compliance

NIST 800-53PCI DSS v4.0.1PCI DSS v7.3.1