| name | cis-aws-storage-6.13 |
| description | Ensure working of EDR |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","edr","disaster-recovery","verification","testing","functionality"] |
| cis_id | 6.13 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-6.1","cis-aws-storage-6.3","cis-aws-storage-6.4","cis-aws-storage-6.6","cis-aws-storage-6.12"] |
| prerequisites | [] |
| severity_boost | {} |
CIS 6.13: Ensure working of EDR (Manual)
Profile Applicability
Description
This control ensures the complete functionality and proper configuration of AWS Elastic Disaster Recovery (EDR). It validates that all components of the EDR system are working correctly, from environment preparation through agent installation, replication, and recovery capabilities.
Rationale
Verifying the working state of EDR is essential to ensure that disaster recovery capabilities are functional when needed. A comprehensive validation of all EDR components ensures that the organization can successfully recover from disasters, minimizing downtime and data loss. This holistic verification approach confirms that all prerequisites, configurations, and processes are properly aligned.
Impact
Ensuring EDR functionality requires:
- Environment preparation and validation
- Source server configuration
- Staging area setup
- Replication agent installation
- Network connectivity verification
- Security group configuration
- Encryption implementation
- Point-in-time policy configuration
Benefits:
- Confidence in disaster recovery capability
- Early detection of configuration issues
- Validated recovery processes
- Verified data protection
- Compliance readiness
Audit Procedure
Via AWS Console
This control encompasses the complete EDR setup and verification process:
-
Preparing the Environment for EDR:
- Before getting started with EDR, you must prepare the environment that you want to back up.
-
Preparing the Source Server:
- Allow direct access to Elastic Disaster Recovery and Amazon S3 AWS service API endpoints through HTTPS protocol (TCP port 443).
- Direct outbound TCP port 1500 from the source server to the staging area subnet, which contains the replication servers.
-
Preparing the Staging Area Subnet:
- Allow Direct access to EDR, S3, and EC2 through HTTPS protocol (TCP port 443)
- Direct inbound TCP port 1500 for replication traffic
-
Accessing the AWS Elastic Disaster Recovery Console:
- Search for "AWS Elastic Disaster Recovery" in the AWS Console.
- Select "Elastic Disaster Recovery"