用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-database-10-10命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-database-10.10 |
| description | Ensure Database has automated Backups enabled |
| category | cis-database |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","database","timestream","time-series","backup","aws-backup","recovery"] |
| cis_id | 10.10 |
| cis_benchmark | CIS AWS Database Services Benchmark v2.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-database-10.8","cis-aws-database-10.9"] |
| prerequisites | [] |
| severity_boost | {} |
Ensure that Amazon Timestream tables have automated backups enabled through AWS Backup with a defined backup schedule and retention policy. AWS Backup provides scheduled, automated backup functionality for Timestream tables, creating regular point-in-time snapshots that are retained according to a configurable lifecycle policy.
Amazon Timestream stores critical time-series data that is often mission-critical for monitoring, analytics, and operational intelligence. Automated backups through AWS Backup ensure that Timestream tables are continuously protected without requiring manual intervention, and can be rapidly restored in the event of accidental deletion, data corruption, misconfiguration, or application errors.
Enabling automated backups for Timestream ensures that time-series data is regularly captured in durable backups and recoverable to any point within the configured retention window, providing strong protection against accidental loss and data corruption.
Important Note: Amazon Timestream does not have a native automated backup feature built into the service. Instead, backups are managed through AWS Backup, which provides scheduled, on-demand, and lifecycle-managed backup functionality for Timestream tables.
Check if automated backups are enabled via AWS Backup Service:
List backup plans:
aws backup list-backup-plans --query "BackupPlansList[].BackupPlanName" --output table
For each backup plan, list all backup selections (resource assignments):
aws backup list-backup-selections --backup-plan-id <your-backup-plan-id> --query "BackupSelections[].SelectionId" --output text
For each selection, list assigned resources and search for your database:
aws backup get-backup-selection --backup-plan-id <your-backup-plan-id> --selection-id <selection-id> --query "BackupSelection.Resources" --output text
aws backup get-backup-plan --backup-plan-id <your-backup-plan-id>
Look for the "Lifecycle" fields in each backup rule:
Timestream tables should be assigned to an AWS Backup plan with appropriate schedule and retention policies configured.
aws backup create-backup-plan --backup-plan '{
"BackupPlanName": "<BackupPlanName>",
"Rules": [
{
"RuleName": "Scheduled-OnDemand-Snapshots",
"TargetBackupVaultName": "Default",
"ScheduleExpression": "cron(0 3 ? * SUN *)",
"StartWindowMinutes": 120,
"CompletionWindowMinutes": 360,
"Lifecycle": { "DeleteAfterDays": 90 },
"RecoveryPointTags": { "BackupType": "OnDemand" }
}
]
}'
This command outputs the BackupPlanId necessary for the next step.
Replace with the ID from Step 1 and with your Timestream table ARN.
aws backup create-backup-selection --backup-plan-id <BackupPlanId> --backup-selection '{ "SelectionName": "timestream-tables", "IamRoleArn": "arn:aws:iam:::role/AWSBackupServiceRolePolicyForBackup", "Resources": ["<TableArn>"] }'
Amazon Timestream does not have native automated backups. Backups must be configured through AWS Backup.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 11 Data Recovery | x | x | x |
Level 1 | Manual