Amazon DocumentDB clusters should have adequate backup retention
Description
This control checks whether an Amazon DocumentDB cluster has a backup retention period greater than or equal to the specified time frame. The control fails if the backup retention period is less than the specified time frame. Unless you provide a custom parameter value for the backup retention period, Security Hub uses a default value of 7 days. Adequate backup retention ensures that you can recover your data in case of accidental deletion, corruption, or other data loss scenarios, which is essential for business continuity and disaster recovery.
Remediation
Configure your Amazon DocumentDB cluster to have an adequate backup retention period of at least 7 days.
Steps
- Open the Amazon DocumentDB console.
- Choose 'Clusters' from the navigation pane.
- Select the cluster you want to modify.
- Choose 'Modify'.
- In the 'Backup' section, set 'Backup retention period' to at least 7 days.
- Choose 'Continue' and then 'Modify cluster'.