| name | cis-aws-database-10.10 |
| description | Ensure Database has automated Backups enabled |
| category | cis-database |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","database","timestream","time-series","backup","aws-backup","recovery"] |
| cis_id | 10.10 |
| cis_benchmark | CIS AWS Database Services Benchmark v2.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-database-10.8","cis-aws-database-10.9"] |
| prerequisites | [] |
| severity_boost | {} |
10.10 Ensure Database has automated Backups enabled (Manual)
Description
Ensure that Amazon Timestream tables have automated backups enabled through AWS Backup with a defined backup schedule and retention policy. AWS Backup provides scheduled, automated backup functionality for Timestream tables, creating regular point-in-time snapshots that are retained according to a configurable lifecycle policy.
Rationale
Amazon Timestream stores critical time-series data that is often mission-critical for monitoring, analytics, and operational intelligence. Automated backups through AWS Backup ensure that Timestream tables are continuously protected without requiring manual intervention, and can be rapidly restored in the event of accidental deletion, data corruption, misconfiguration, or application errors.
Impact
Enabling automated backups for Timestream ensures that time-series data is regularly captured in durable backups and recoverable to any point within the configured retention window, providing strong protection against accidental loss and data corruption.
Audit Procedure
Using AWS CLI
Important Note: Amazon Timestream does not have a native automated backup feature built into the service. Instead, backups are managed through AWS Backup, which provides scheduled, on-demand, and lifecycle-managed backup functionality for Timestream tables.
Check if automated backups are enabled via AWS Backup Service:
- Check if Timestream Database is Assigned to a Backup Plan:
List backup plans:
aws backup list-backup-plans --query "BackupPlansList[].BackupPlanName" --output table
For each backup plan, list all backup selections (resource assignments):
aws backup list-backup-selections --backup-plan-id <your-backup-plan-id> --query "BackupSelections[].SelectionId" --output text
For each selection, list assigned resources and search for your database:
aws backup get-backup-selection --backup-plan-id <your-backup-plan-id> --selection-id <selection-id> --query "BackupSelection.Resources" --output text
- If your table ARN appears in any selection, it is protected by the backup plan.
- Verify Backup Plan Configuration:
aws backup get-backup-plan --backup-plan-id <your-backup-plan-id>
Look for the "Lifecycle" fields in each backup rule:
- "DeleteAfterDays" is the retention period.