CIS AWS Database Services Benchmark v1.0.0

Ensure Regular Updates and Patches are Installed
Profile Applicability  • Level 1 Description  Ensure the database engine receives regular updates and patches to mitigate known vulnerabilities and strengt...
Tue, 6 May, 2025 at 5:35 AM
Ensure Audit Logging is Enabled
Profile Applicability  • Level 1 Description  Enable audit logging to capture database activities, including login attempts, queries, and modifications. Lo...
Tue, 6 May, 2025 at 5:40 AM
Ensure Fine-Grained Access Control is Enabled
Profile Applicability Level 1 Description Enable fine-grained access control (FGAC) in database services such as Amazon Timestream and DynamoDB to ...
Tue, 6 May, 2025 at 5:49 AM
Ensure Access Control and Authentication is Enabled
Profile Applicability Level 1 Description This control ensures that AWS access control and authentication mechanisms are enabled for managing and p...
Tue, 6 May, 2025 at 6:03 AM
Ensure Encryption in Transit is Configured
Profile Applicability  Level 1 Description Ensure that all data exchanged between database services, clients, and internal systems is encrypted duri...
Tue, 6 May, 2025 at 6:32 AM
Ensure Data Ingestion is Secure
Profile Applicability: This check applies to all AWS accounts where data ingestion is a critical component of the system, specifically for ensuring the sec...
Tue, 6 May, 2025 at 6:38 AM
Ensure Monitoring and Logging is Enabled
Profile Applicability: Level 1 Description:  Monitoring and logging are essential for tracking database performance, detecting anomalies, and ensuring ...
Tue, 6 May, 2025 at 6:52 AM
Ensure Security Configurations are Reviewed Regularly (Manual)
Profile Applicability:  Level 1 Description:  Regularly reviewing security configurations ensures that any changes in AWS services, compliance requirements...
Wed, 7 May, 2025 at 12:01 AM
Ensure Authentication and Access Control is Enabled
 Profile Applicability:  Level 1 Description:  Authentication and access control are critical to securing databases by ensuring that only authorized users ...
Wed, 7 May, 2025 at 12:13 AM
Ensure Data at Rest and in Transit is Encrypted
Profile Applicability:  Level 1 Description:  This check ensures that data is protected both while stored in the database (data at rest) and while transmit...
Wed, 7 May, 2025 at 12:27 AM