turbot/alicloud_compliance

GitHub
Loading controls...

Control: 6.4 Ensure that 'Auditing' Retention is 'greater than 6 months'

Description

Database SQL Audit Retention should be configured to be greater than 90 days.

Remediation

From Console

  1. Logon to RDS Console.
  2. In the upper-left corner, select the region of the target instance.
  3. Locate the target instance, and click the instance ID.
  4. In the left-side navigation pane, select SQL Explore.
  5. Click Service Setting button on the top right corner.
  6. In the service setting page, enable Activate SQL Explore, set the storage duration as ‘6 months’ or longer.

Usage

Run the control in your terminal:

steampipe check alicloud_compliance.control.cis_v100_6_4

Snapshot and share results via Steampipe Cloud:

steampipe login
steampipe check --share alicloud_compliance.control.cis_v100_6_4

SQL

This control uses a named query:

rds_instance_sql_audit_retention_period_180_days

Tags