High
GuardDuty
Regional
GuardDuty RDS Protection should be enabled
PCI DSS v4.0.1PCI DSS v11.5.1
Description
Confirms that GuardDuty RDS Protection is enabled across all accounts to analyze and profile RDS login activity for access threats to Aurora databases.
Remediation
To enable GuardDuty RDS Protection, you need to configure the RDS Protection settings in GuardDuty.
Steps
- Navigate to the Amazon GuardDuty console
- Go to 'Settings' in the left navigation
- Select 'RDS Protection'
- Enable 'RDS Protection'
- Configure the protection settings as needed
- Save the configuration
- Verify that RDS Protection is active
Compliance
PCI DSS v4.0.1PCI DSS v11.5.1