用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-database-3-9命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-database-3.9 |
| description | Ensure Monitoring and Logging is Enabled |
| category | cis-database |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","database","rds","monitoring","logging","cloudwatch","audit"] |
| cis_id | 3.9 |
| cis_benchmark | CIS AWS Database Services Benchmark v2.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-database-3.11"] |
| prerequisites | [] |
| severity_boost | {} |
This control ensures that monitoring and logging are enabled for Amazon RDS instances to detect, investigate, and respond to security events and operational issues.
Monitoring and logging provide visibility into database activity, enabling detection of unauthorized access, performance issues, and security incidents.
If the individual is not monitoring and logging their activity it allows the attacker to attack the system and extract or destroy data.
Sign into the AWS Management Console
Open the Amazon RDS Console
Find Services search bar or by directly accessing the console at https://console.aws.amazon.com/rds/.Select the RDS Instance
Configuration or Monitoring & Logs section.Enable Enhanced Monitoring
Monitoring section.Modify button or Edit option to enable enhanced monitoring.Continue or Save to apply the changes.Enable Enhanced Logging
Logs or Monitoring & Logs section.Modify button or Edit option to enable enhanced logging.Continue or Save to apply the changes.Configure CloudWatch Alarms (Optional)
Alarms in the Amazon RDS console menu.Create alarm to create a CloudWatch alarm to monitor specific metrics or log events.Create to create the CloudWatch alarm.Monitor and Analyze the Metrics and Logs
Set Up Automated Actions (Optional)
Event subscriptions in the left-side menu.Create event subscription to set up automated actions based on specific events or log entries.Create to create the event subscription.Monitor and Respond to Alerts
Enhanced Monitoring should be enabled, and appropriate log types (general, error, slow query, audit) should be configured and published to CloudWatch Logs or S3.
Follow the audit steps above to enable Enhanced Monitoring and configure logging. Set up CloudWatch alarms for critical metrics and event subscriptions for automated alerting.
Enhanced Monitoring is disabled by default. Basic monitoring with 1-minute CloudWatch metrics is available by default. Database engine logs must be explicitly enabled and published.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 8 Audit Log Management | |||
| v7 | 6 Maintenance, Monitoring and Analysis of Audit Logs |
Level 1 | Manual