More Info:

The automated snapshot retention period set for your AWS Redshift clusters should be a positive number, meaning that automated backups are enabled for the clusters.

Risk Level

Low

Address

Security

Compliance Standards

SOC2, HIPAA, GDPR, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration of Redshift Automated Snapshots not having retention period enabled in AWS, follow these steps using the AWS Management Console:

  1. Login to AWS Console: Go to the AWS Management Console and log in with your credentials.

  2. Navigate to Amazon Redshift: Click on the “Services” dropdown menu at the top of the page, and then select “Redshift” under the Analytics section.

  3. Select your Redshift Cluster: From the Redshift dashboard, select the Redshift cluster for which you want to enable the retention period for automated snapshots.

  4. Modify Cluster: In the cluster details page, click on the cluster identifier link to go to the cluster details.

  5. Configure Automated Snapshots: In the cluster details page, scroll down to the “Cluster snapshots” section and click on the “Modify” button.

  6. Enable Retention Period: In the Modify cluster snapshot settings page, locate the “Automated snapshots” section. Here, you will find the option to set the retention period for automated snapshots.

  7. Set Retention Period: Check the box next to “Enable” to enable automated snapshots and set a retention period using the dropdown menu. You can choose a retention period between 1 to 35 days.

  8. Save Changes: Once you have set the retention period, scroll down to the bottom of the page and click on the “Modify cluster” button to save the changes.

  9. Verify Configuration: After saving the changes, AWS Redshift will start taking automated snapshots with the configured retention period.

By following these steps, you have successfully remediated the misconfiguration of Redshift Automated Snapshots not having retention period enabled in AWS.

Additional Reading: