Critical DocumentDB Regional

Amazon DocumentDB manual cluster snapshots should not be public

NIST 800-53PCI DSS v4.0.1PCI DSS v1.4.4ISO 27001

Description

This control checks whether an Amazon DocumentDB manual cluster snapshot is public. The control fails if the manual cluster snapshot is public. An Amazon DocumentDB manual cluster snapshot should not be public unless intended. If you share an unencrypted manual snapshot as public, the snapshot is available to all AWS accounts. Public snapshots may result in unintended data exposure.


Remediation

Make your Amazon DocumentDB manual cluster snapshots private by removing public access permissions.

Steps

  1. Open the Amazon DocumentDB console.
  2. Choose 'Snapshots' from the navigation pane.
  3. Select the manual snapshot you want to modify.
  4. Choose 'Actions' and then 'Manage access'.
  5. Remove 'all' from the 'Public access' section.
  6. Choose 'Save changes'.

Compliance

NIST 800-53PCI DSS v4.0.1PCI DSS v1.4.4ISO 27001