Neptune DB clusters should have deletion protection enabled
Description
This control checks if a Neptune DB cluster has deletion protection enabled. The control fails if a Neptune DB cluster doesn't have deletion protection enabled. Enabling cluster deletion protection offers an additional layer of protection against accidental database deletion or deletion by an unauthorized user. A Neptune DB cluster can't be deleted while deletion protection is enabled. You must first disable deletion protection before a delete request can succeed.
Remediation
To remediate Neptune DB clusters without deletion protection enabled, you need to enable deletion protection for the cluster.
Steps
- Navigate to the Amazon Neptune console
- Select the DB cluster that needs remediation
- Click on 'Modify' to edit the cluster configuration
- In the 'Backup' section, locate 'Deletion protection'
- Enable 'Deletion protection' by checking the box
- Review the deletion protection settings
- Apply the changes during the next maintenance window or immediately
- Verify that deletion protection is enabled in the cluster details
- Test that the cluster cannot be deleted while protection is enabled
- Document the change and inform relevant team members