| name | cis-aws-storage-6.10 |
| description | Ensure execution of a Disaster Recovery Failover |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","edr","disaster-recovery","failover","recovery","business-continuity"] |
| cis_id | 6.10 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-6.8","cis-aws-storage-6.9","cis-aws-storage-6.11"] |
| prerequisites | [] |
| severity_boost | {} |
CIS 6.10: Ensure execution of a Disaster Recovery Failover (Manual)
Profile Applicability
Description
Execute a comprehensive disaster recovery failover to transition operations from the primary system to a backup system during disruptions. This process includes ensuring all critical data and applications are accurately replicated to the backup site for seamless operational continuity. Regularly test and document the failover process to identify and resolve any issues, maintaining readiness to minimize downtime and data loss during real disasters.
Rationale
Executing a comprehensive disaster recovery failover is essential to ensure operational continuity during disruptions. Accurate replication of critical data and applications to the backup site guarantees that business operations can continue seamlessly. Regular testing and documentation of the failover process help identify and resolve potential issues, maintaining a state of readiness and minimizing downtime and data loss in actual disaster scenarios.
Impact
Failover execution requires:
- Comprehensive planning and preparation
- Testing in non-production environments first
- Documented procedures
- Trained personnel
- Potential brief service interruption
- Post-failover validation
Benefits:
- Validates failover capability
- Ensures business continuity
- Minimizes downtime
- Protects against data loss
- Builds confidence in DR capabilities
- Identifies issues before real disasters
Audit Procedure
Via AWS Console
Follow the steps where we learned how to conduct a recovery drill with the below modifications:
-
Select Server for Failover:
- Choose the server that you want to recover and failover.
- On the initiate recovery job menu, choose "initiate recovery."
-
Choose Recovery Point:
- Choose a point in time to recover from backup.
-
Initiate Recovery Job:
- Choose initiate recovery to create a recovery job.
Note: You can use the job details to monitor the progress and status of the recovery job.
-
Verify Completion:
- After the recovery job has completed, the last recovery result of your source server will report "successful."