| name | cis-aws-storage-6.1 |
| description | Ensure Elastic Disaster Recovery is Configured |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","edr","disaster-recovery","backup","resilience","business-continuity"] |
| cis_id | 6.1 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-6.2","cis-aws-storage-6.3","cis-aws-storage-6.4","cis-aws-storage-6.8","cis-aws-storage-6.9"] |
| prerequisites | [] |
| severity_boost | {} |
CIS 6.1: Ensure Elastic Disaster Recovery is Configured (Manual)
Profile Applicability
Description
AWS Elastic Disaster Recovery is a service that enables you to create and maintain backups of your workloads on AWS, specifically your servers. This service is crucial for ensuring high resilience for your AWS workloads. It operates by establishing and maintaining backups in selected AWS regions, guaranteeing that your data is safe, durable, and highly available in the event of issues in the primary availability zone or region where your AWS server is located.
AWS Elastic Disaster Recovery is essential to providing high resilience to your AWS workloads. It works by establishing and maintaining backups in AWS regions of your choosing, to ensure that your backups are safe, durable, and highly available if something goes wrong in the availability zone or region that your AWS server resides.
Rationale
AWS Elastic Disaster Recovery is crucial for establishing high resiliency in the cloud, synonymous with effective disaster recovery. High resiliency measures your organization's ability to respond to and recover from disasters impacting IT infrastructure. Achieving high resiliency minimizes downtime and long-term costs associated with outages, while low resiliency can result in prolonged downtime, potential data loss, and even permanent infrastructure damage.
Impact
Implementing AWS Elastic Disaster Recovery requires planning, configuration, and ongoing maintenance. Organizations must allocate resources for setup, testing, and monitoring to ensure the disaster recovery solution remains effective.
Audit Procedure
Via AWS Console
-
Review Disaster Recovery Plans:
- Log in to the AWS Management Console.
- Navigate to the AWS Elastic Disaster Recovery service.
- Locate and open the disaster recovery plans.
- Verify that the plans are current and comprehensive, covering all critical workloads.
- Ensure that the plans specify clear recovery time objectives (RTO) and recovery point objectives (RPO).
-
Check Backup Configurations:
- In the AWS Elastic Disaster Recovery dashboard, review the list of protected servers and workloads.
- Confirm that backups are enabled for all critical servers and workloads.
- Verify the backup schedule and frequency to ensure they meet organizational requirements.
- Check that backups are being stored in the correct AWS regions as specified in the disaster recovery plan.
-
Test Recovery Procedures: