Critical
DocumentDB
Regional
Amazon DocumentDB manual cluster snapshots should not be public
NIST 800-53PCI DSS v4.0.1PCI DSS v1.4.4ISO 27001
Description
This control checks whether an Amazon DocumentDB manual cluster snapshot is public. The control fails if the manual cluster snapshot is public. An Amazon DocumentDB manual cluster snapshot should not be public unless intended. If you share an unencrypted manual snapshot as public, the snapshot is available to all AWS accounts. Public snapshots may result in unintended data exposure.
Remediation
Make your Amazon DocumentDB manual cluster snapshots private by removing public access permissions.
Steps
- Open the Amazon DocumentDB console.
- Choose 'Snapshots' from the navigation pane.
- Select the manual snapshot you want to modify.
- Choose 'Actions' and then 'Manage access'.
- Remove 'all' from the 'Public access' section.
- Choose 'Save changes'.
Compliance
NIST 800-53PCI DSS v4.0.1PCI DSS v1.4.4ISO 27001