Medium
DMS
Regional
DMS replication tasks for the source database should have logging enabled
NIST 800-53PCI DSS v4.0.1PCI DSS v10.4.2
Description
Verifies that DMS replication tasks have logging enabled at LOGGER_SEVERITY_DEFAULT or higher for SOURCE_CAPTURE and SOURCE_UNLOAD components.
Remediation
Enable logging for DMS replication tasks with appropriate severity levels for source database operations.
Steps
- Navigate to the AWS DMS console
- Go to the Database migration tasks section
- Select the replication task that needs logging
- Modify the task settings
- In the 'Logging' section, enable 'Source capture logging' and 'Source unload logging'
- Set the severity level to at least 'LOGGER_SEVERITY_DEFAULT' or higher
- Configure CloudWatch Logs destination if needed
- Save the configuration changes
- Verify that logging is now enabled for the source database operations
Compliance
NIST 800-53PCI DSS v4.0.1PCI DSS v10.4.2