lacework-global-390
ElastiCache Redis clusters should have automatic backup enabled (Automated)
Description
Amazon ElastiCache for Redis clusters can back up their data. You can use the backup to restore a cluster or seed a new cluster. The backup consists of the cluster's metadata, along with all of the data in the cluster. Amazon Simple Storage Service (S3) provides durable storage for all backups.
Remediation
From the AWS Console:
- Log in to the AWS Management Console.
- Click Services.
- Select Database > ElastiCache.
- Under Resources, click Redis caches.
- For the cache of interest, select it and click Actions > Modify.
- Under Backup, select Enable automatic backups and set a Backup retention period of 1 day or more.
- Once finished, click Preview changes.
- Under Schedule modifications, select Yes for Apply immediately, and click Modify.
From CLI:
aws elasticache modify-cache-cluster --cache-cluster-id <cluster_id> --snapshot-retention-limit <number_of_days> --apply-immediately
References
https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-1
https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/backups-automatic.html