Ensure automatic minor version upgrade is enabled for Amazon Relational Database Service (Amazon RDS) instances

HIGH

Description

AWS RDS instances have auto minor version upgrade disabled which may cause RDS instances to miss important updates and bug fixes.

Remediation

In AWS Console -

  1. Sign in to the AWS Console and go to the AWS RDS Console.
  2. In the RDS Dashboard, click on Databases.
  3. Select Modify to modify the instance of your choice.
  4. Select the Auto Minor Version Upgrade option to enable it.

In Terraform -

  1. In the aws_db_instance resource, set the auto_minor_version_upgrade field to true.

References:
https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_UpgradeDBInstance.Upgrading.html#USER_UpgradeDBInstance.Upgrading.AutoMinorVersionUpgrades
https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/db_instance#auto_minor_version_upgrade

Policy Details

Rule Reference ID: AC_AWS_0056
CSP: AWS
Remediation Available: Yes
Resource: aws_db_instance
Resource Category: Database
Resource Type: DB Instance

Frameworks