Medium
DMS
Regional
DMS endpoints for Neptune databases should have IAM authorization enabled
NIST 800-53PCI DSS v4.0.1PCI DSS v7.3.1
Description
Verifies that AWS DMS endpoints for Neptune databases use IAM authorization, enabling fine-grained access control through a service access role.
Remediation
Enable IAM authorization for your DMS endpoints that connect to Neptune databases to ensure fine-grained access control.
Steps
- Navigate to the AWS DMS console
- Go to the Endpoints section
- Select the Neptune endpoint that needs IAM authorization
- Modify the endpoint configuration
- In the 'Authentication' section, enable 'IAM database authentication'
- Configure the 'Service access role ARN' parameter
- Ensure the IAM role has appropriate permissions for Neptune access
- Save the configuration changes
- Verify that IAM authorization is now enabled for the Neptune endpoint
Compliance
NIST 800-53PCI DSS v4.0.1PCI DSS v7.3.1