Updated on 2025-01-20 GMT+08:00

Conformance Package for RDS

The following table lists the rules and solutions included in this conformance package template.

Table 1 Conformance package description

Rule

Cloud Service

Description

rds-instance-enable-backup

rds

If backup is not enabled for an RDS instance, this instance is noncompliant.

rds-instance-enable-errorLog

rds

If error log collection is not enabled for an RDS instance, this instance is noncompliant.

rds-instance-enable-slowLog

rds

If an RDS instance does not support slow query logs, this instance is noncompliant.

rds-instance-multi-az-support

rds

If an RDS instance does not support multi-AZ deployment, this RDS instance is noncompliant.

rds-instance-no-public-ip

rds

If an RDS instance has an EIP attached, this RDS instance is noncompliant.

rds-instances-enable-kms

rds

If KMS encryption is not enabled for an RDS instance, this instance is noncompliant.

rds-instance-enable-auditLog

rds

If an RDS instance does not have the audit log enabled or has audit logs kept for less than the specified number of days, this instance is noncompliant.

rds-instance-engine-version-check

rds

If the version of an RDS instance engine is earlier than the specified version, this instance is noncompliant.

rds-instance-port-check

rds

If an RDS instance has unallowed ports enabled, this instance is noncompliant.

rds-instance-ssl-enable

rds

If SSL is not enabled for an RDS instance, this instance is noncompliant.