AWS RDS Aurora Terraform module

Upstream version 10.4.1
7 controls from NIS2 Directive (EU 2022/2555) requirements

Terraform Module Source

nis2.compliance.tf/terraform-aws-modules/rds-aurora/aws

Behavioral Summary

This module modifies 4 variable defaults and makes 0 resource changes from the upstream module. All changes are driven by compliance controls and can be reviewed in detail below.

Your Code Impact

If you are migrating from the upstream module, the enforced default changes mean your existing configurations will automatically gain compliance controls. Variables you have explicitly set will continue to use your values. Review the diff below to understand exactly what changes.

Compared to terraform-aws-modules/rds-aurora/aws@10.4.14 changes

Variables Changed

4
VariableUpstreamCTFReasonControl
backtrack_window-72This control checks whether AWS Aurora clusters have backtracking enabled. Backups help you to recover more quickly from a security incident. They also strengthen the resilience of your systems. Aurora backtracking reduces the time to recover a database to a point in time. It does not require a database restore to so.rds_db_cluster_aurora_backtracking_enabled
cloudwatch_log_group_retention_in_days7365Ensure a minimum duration of event log data is retained for your log groups to help with troubleshooting and forensics investigations.cloudwatch_log_group_retention_period_365
cluster_monitoring_interval060Enable AWS Relational Database Service (AWS RDS) to help monitor AWS RDS availability. This provides detailed visibility into the health of your AWS RDS database instances.rds_db_instance_and_cluster_enhanced_monitoring_enabled
iam_database_authentication_enabled-trueChecks if an AWS RDS Cluster has AWS Identity and Access Management (IAM) authentication enabled. The rule is non-compliant if an RDS Cluster does not have IAM authentication enabled.rds_db_cluster_iam_authentication_enabled