Stay informed about the latest security updates and patches released by Amazon for DocumentDB. Regularly apply updates and patches to your DocumentDB instances to protect against known vulnerabilities.
Rationale
Regular patching and updates are essential to protect DocumentDB instances from known security vulnerabilities and ensure the database engine is running with the latest security fixes.
Impact
Helps the organization reduce their security risk by regularly updating and patching their database and database engine. Regularly updating and scanning for any weaknesses in the company can bring up possible vulnerabilities that could have led to potential cyber-attack.
Audit Procedure
Using AWS Console
Stay Informed
Stay updated with Amazon DocumentDB announcements, release notes, and security bulletins.
Subscribe to AWS newsletters, forums, and notifications to receive timely updates regarding updates and patches.
Plan for Maintenance Windows
Determine a suitable maintenance window to apply updates and patches to your DocumentDB cluster.
Consider the impact on your applications and users when scheduling the maintenance window.
Monitor the AWS Management Console
Regularly check the AWS Management Console for notifications related to available updates and patches for your DocumentDB cluster.
The console will provide information on new versions and available patches.
Review the Release Notes and Changelog
Before applying any updates or patches, review the release notes and changelog for the new version or patch.
Pay attention to any compatibility or breaking changes that may require application adjustments.
Create a Test Environment (Optional)
If feasible, create a separate test environment that closely resembles your production environment.
Deploy a copy of your DocumentDB cluster in the test environment to test the updates and patches before applying them to production.
Apply Updates and Patches
During the scheduled maintenance window, initiate the process to apply updates and patches to your DocumentDB cluster.
Follow the recommended procedure provided by AWS, which may involve a few simple clicks in the AWS Management Console.
Ensure that you select the appropriate version or patch to apply.
Monitor the Update Process
Monitor the progress of the update or patch application for your DocumentDB cluster.
AWS will provide status updates during the process to keep you informed.
Verify Post-Update Functionality
After the update or patch is applied, test the functionality of your applications that rely on the DocumentDB cluster.
Verify that your applications are working as expected and that any integration or dependencies are intact.
Review and Update Documentation
Update your documentation, including standard operating procedures (SOPs), to reflect the new version or patch applied to the DocumentDB cluster.
Document any changes or considerations specific to the update or patch.
Monitor for New Updates
Continuously monitor for new updates and patches released by AWS for DocumentDB.
Repeat the update process regularly to ensure your DocumentDB cluster remains up to date with the latest security enhancements and bug fixes.
Expected Result
DocumentDB clusters are running the latest available engine version with all applicable security patches applied.
Remediation
Using AWS Console
Follow the audit procedure steps to identify available updates and apply them during scheduled maintenance windows. Use the AWS Management Console to modify the DocumentDB cluster and apply the latest engine version.
Default Value
Amazon DocumentDB applies minor patches automatically during the configured maintenance window. Major version upgrades require manual action.
1---2name: cis-aws-database-7-73description: Ensure Regular Updates and Patches4---56# 7.7 Ensure Regular Updates and Patches (Manual)78## Description910Stay informed about the latest security updates and patches released by Amazon for DocumentDB. Regularly apply updates and patches to your DocumentDB instances to protect against known vulnerabilities.1112## Rationale1314Regular patching and updates are essential to protect DocumentDB instances from known security vulnerabilities and ensure the database engine is running with the latest security fixes.1516## Impact1718Helps the organization reduce their security risk by regularly updating and patching their database and database engine. Regularly updating and scanning for any weaknesses in the company can bring up possible vulnerabilities that could have led to potential cyber-attack.1920## Audit Procedure2122### Using AWS Console23241. Stay Informed25 - Stay updated with Amazon DocumentDB announcements, release notes, and security bulletins.26 - Subscribe to AWS newsletters, forums, and notifications to receive timely updates regarding updates and patches.27282. Plan for Maintenance Windows29 - Determine a suitable maintenance window to apply updates and patches to your DocumentDB cluster.30 - Consider the impact on your applications and users when scheduling the maintenance window.31323. Monitor the AWS Management Console33 - Regularly check the AWS Management Console for notifications related to available updates and patches for your DocumentDB cluster.34 - The console will provide information on new versions and available patches.35364. Review the Release Notes and Changelog37 - Before applying any updates or patches, review the release notes and changelog for the new version or patch.38 - Pay attention to any compatibility or breaking changes that may require application adjustments.39405. Create a Test Environment (Optional)41 - If feasible, create a separate test environment that closely resembles your production environment.42 - Deploy a copy of your DocumentDB cluster in the test environment to test the updates and patches before applying them to production.43446. Apply Updates and Patches45 - During the scheduled maintenance window, initiate the process to apply updates and patches to your DocumentDB cluster.46 - Follow the recommended procedure provided by AWS, which may involve a few simple clicks in the AWS Management Console.47 - Ensure that you select the appropriate version or patch to apply.48497. Monitor the Update Process50 - Monitor the progress of the update or patch application for your DocumentDB cluster.51 - AWS will provide status updates during the process to keep you informed.52538. Verify Post-Update Functionality54 - After the update or patch is applied, test the functionality of your applications that rely on the DocumentDB cluster.55 - Verify that your applications are working as expected and that any integration or dependencies are intact.56579. Review and Update Documentation58 - Update your documentation, including standard operating procedures (SOPs), to reflect the new version or patch applied to the DocumentDB cluster.59 - Document any changes or considerations specific to the update or patch.606110. Monitor for New Updates62 - Continuously monitor for new updates and patches released by AWS for DocumentDB.63 - Repeat the update process regularly to ensure your DocumentDB cluster remains up to date with the latest security enhancements and bug fixes.6465## Expected Result6667DocumentDB clusters are running the latest available engine version with all applicable security patches applied.6869## Remediation7071### Using AWS Console7273Follow the audit procedure steps to identify available updates and apply them during scheduled maintenance windows. Use the AWS Management Console to modify the DocumentDB cluster and apply the latest engine version.7475## Default Value7677Amazon DocumentDB applies minor patches automatically during the configured maintenance window. Major version upgrades require manual action.7879## References80811. https://aws.amazon.com/products/databases/8283## CIS Controls8485| Controls Version | Control | IG 1 | IG 2 | IG 3 |86| ---------------- | ------------------------------------- | ---- | ---- | ---- |87| v8 | 7 Continuous Vulnerability Management | | | |88| v7 | 3 Continuous Vulnerability Management | | | |8990## Profile9192Level 1 | Manual
Run npx skillmds@latest add cyberstrikeus/cis-aws-database-7-7 in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Ensure Regular Updates and Patches It is listed under DevOps & Infra on SkillMD.
SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
cyberstrikeus (@cyberstrikeus) published this skill. Their other Agent Skills are listed on their SkillMD profile.