| name | cis-aws-storage-6.8 |
| description | Ensure execution of a recovery drill |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","edr","disaster-recovery","drill","testing","recovery-testing","rto","rpo"] |
| cis_id | 6.8 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-6.1","cis-aws-storage-6.7","cis-aws-storage-6.9","cis-aws-storage-6.10"] |
| prerequisites | [] |
| severity_boost | {} |
CIS 6.8: Ensure execution of a recovery drill (Manual)
Profile Applicability
Description
To ensure your organization is prepared for a disaster, it's crucial to verify that your disaster recovery services function as expected. Your IT team should conduct regular recovery drills on your AWS Elastic Recovery Instance to confirm everything operates smoothly and according to plan.
Rationale
Regular recovery drills are essential to verify the functionality of your disaster recovery services and ensure your organization is well-prepared for any disruptions. By conducting these drills on your AWS Elastic Recovery Instance, you can identify and address potential issues before they impact operations. This proactive approach enhances the reliability and effectiveness of your disaster recovery plan, providing confidence that your systems can recover swiftly and efficiently in the event of a disaster.
Impact
Recovery drills require:
- Planning and scheduling
- Non-production environment for testing
- Time and resources for execution
- Documentation of results
- Potential discovery of configuration issues
- Updates to recovery procedures based on findings
Benefits:
- Validates disaster recovery plan effectiveness
- Identifies potential issues before real disasters
- Ensures team familiarity with recovery procedures
- Confirms RTO and RPO objectives are achievable
- Provides confidence in recovery capabilities
Audit Procedure
Via AWS Console
Steps to perform a recovery drill:
-
Navigate to Source Servers:
- Navigate to source servers tab in AWS Elastic Disaster Recovery Dashboard.
-
Verify Server Status:
- Make sure that all servers you launch show as "Ready" under "status," report as "healthy" in the data replication status column, and that pending actions show as "initiate drill".
-
Initiate Drill:
- Select "initiate drill" under the orange dropdown menu.
- Make sure that you don't initiate a real recovery job.
-
Choose Recovery Point:
- Choose a recovery point. Normally, it makes sense to choose the most recent recovery point, but you can also choose a recovery point from earlier.
-