CIS 6.8: Ensure execution of a recovery drill (Manual)
Profile Applicability
Level: 2
Description
To ensure your organization is prepared for a disaster, it's crucial to verify that your disaster recovery services function as expected. Your IT team should conduct regular recovery drills on your AWS Elastic Recovery Instance to confirm everything operates smoothly and according to plan.
Rationale
Regular recovery drills are essential to verify the functionality of your disaster recovery services and ensure your organization is well-prepared for any disruptions. By conducting these drills on your AWS Elastic Recovery Instance, you can identify and address potential issues before they impact operations. This proactive approach enhances the reliability and effectiveness of your disaster recovery plan, providing confidence that your systems can recover swiftly and efficiently in the event of a disaster.
Impact
Recovery drills require:
Planning and scheduling
Non-production environment for testing
Time and resources for execution
Documentation of results
Potential discovery of configuration issues
Updates to recovery procedures based on findings
Benefits:
Validates disaster recovery plan effectiveness
Identifies potential issues before real disasters
Ensures team familiarity with recovery procedures
Confirms RTO and RPO objectives are achievable
Provides confidence in recovery capabilities
Audit Procedure
Via AWS Console
Steps to perform a recovery drill:
Navigate to Source Servers:
Navigate to source servers tab in AWS Elastic Disaster Recovery Dashboard.
Verify Server Status:
Make sure that all servers you launch show as "Ready" under "status," report as "healthy" in the data replication status column, and that pending actions show as "initiate drill".
Initiate Drill:
Select "initiate drill" under the orange dropdown menu.
Make sure that you don't initiate a real recovery job.
Choose Recovery Point:
Choose a recovery point. Normally, it makes sense to choose the most recent recovery point, but you can also choose a recovery point from earlier.
Select Initiate Drill:
Select the orange "initiate drill" button to initiate the recovery drill.
Clean Up:
To complete the recovery drill, clean up your resources by deleting the recovery instance by selecting actions and "terminate recovery instances".
Expected Result
All source servers show status "Ready"
Data replication status reports "healthy"
Pending actions show "initiate drill"
Recovery drill initiated successfully
Recovery point selected (most recent or specific point)
Drill completes without errors
Recovery instance launches successfully
Recovery time measured and documented
Recovery time meets RTO objectives
Recovery point meets RPO objectives
Issues identified and documented
Recovery instances terminated after drill
Resources cleaned up properly
Remediation
Via AWS Console
Prepare for Drill:
Ensure all source servers are in "Ready" status
Verify data replication status is "healthy"
Confirm pending actions show "initiate drill"
Execute Drill:
Navigate to source servers tab in EDR Dashboard
Select "initiate drill" from orange dropdown menu
IMPORTANT: Do not initiate a real recovery job
Choose appropriate recovery point (typically most recent)
Click orange "initiate drill" button
Monitor Drill:
Observe recovery instance launch
Measure and document recovery time
Test recovered instance functionality
Verify data integrity
Document Results:
Record recovery time
Compare against RTO and RPO objectives
Document any issues encountered
Note lessons learned
Clean Up:
Select actions menu
Choose "terminate recovery instances"
Confirm termination
Verify resources are cleaned up
Review and Update:
Review drill results with team
Update recovery procedures as needed
Schedule next drill
Default Value
By default, no recovery drills are scheduled or configured. Organizations must manually plan and execute recovery drills.
11.5 Test Data RecoveryTest backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets.
●
●
v8
17.7 Conduct Routine Incident Response ExercisesPlan and conduct routine incident response exercises and scenarios for key personnel involved in the incident response process to prepare for responding to real-world incidents. Exercises need to test communication channels, decision making, and workflows. Conduct testing on an annual basis, at a minimum.
●
●
v7
10.3 Test Data on Backup MediaTest data integrity on backup media on a regular basis by performing a data restoration process to ensure that the backup is properly working.
●
●
v7
19.7 Conduct Periodic Incident Scenario Sessions for PersonnelPlan and conduct routine incident response exercises and scenarios for the workforce involved in the incident response to maintain awareness and comfort in responding to real world threats. Exercises should test communication channels, decision making, and incident responders technical capabilities using tools and data available to them.
●
●
Profile
Level 2
1---2name: cis-aws-storage-6-83description: Ensure execution of a recovery drill4---56# CIS 6.8: Ensure execution of a recovery drill (Manual)78## Profile Applicability910- **Level:** 21112## Description1314To ensure your organization is prepared for a disaster, it's crucial to verify that your disaster recovery services function as expected. Your IT team should conduct regular recovery drills on your AWS Elastic Recovery Instance to confirm everything operates smoothly and according to plan.1516## Rationale1718Regular recovery drills are essential to verify the functionality of your disaster recovery services and ensure your organization is well-prepared for any disruptions. By conducting these drills on your AWS Elastic Recovery Instance, you can identify and address potential issues before they impact operations. This proactive approach enhances the reliability and effectiveness of your disaster recovery plan, providing confidence that your systems can recover swiftly and efficiently in the event of a disaster.1920## Impact2122Recovery drills require:2324- Planning and scheduling25- Non-production environment for testing26- Time and resources for execution27- Documentation of results28- Potential discovery of configuration issues29- Updates to recovery procedures based on findings3031Benefits:3233- Validates disaster recovery plan effectiveness34- Identifies potential issues before real disasters35- Ensures team familiarity with recovery procedures36- Confirms RTO and RPO objectives are achievable37- Provides confidence in recovery capabilities3839## Audit Procedure4041### Via AWS Console4243**Steps to perform a recovery drill:**44451. **Navigate to Source Servers:**46 - Navigate to source servers tab in AWS Elastic Disaster Recovery Dashboard.47482. **Verify Server Status:**49 - Make sure that all servers you launch show as "Ready" under "status," report as "healthy" in the data replication status column, and that pending actions show as "initiate drill".50513. **Initiate Drill:**52 - Select "initiate drill" under the orange dropdown menu.53 - Make sure that you don't initiate a real recovery job.54554. **Choose Recovery Point:**56 - Choose a recovery point. Normally, it makes sense to choose the most recent recovery point, but you can also choose a recovery point from earlier.57585. **Select Initiate Drill:**59 - Select the orange "initiate drill" button to initiate the recovery drill.60616. **Clean Up:**62 - To complete the recovery drill, clean up your resources by deleting the recovery instance by selecting actions and "terminate recovery instances".6364## Expected Result6566- All source servers show status "Ready"67- Data replication status reports "healthy"68- Pending actions show "initiate drill"69- Recovery drill initiated successfully70- Recovery point selected (most recent or specific point)71- Drill completes without errors72- Recovery instance launches successfully73- Recovery time measured and documented74- Recovery time meets RTO objectives75- Recovery point meets RPO objectives76- Issues identified and documented77- Recovery instances terminated after drill78- Resources cleaned up properly7980## Remediation8182### Via AWS Console83841. **Prepare for Drill:**85 - Ensure all source servers are in "Ready" status86 - Verify data replication status is "healthy"87 - Confirm pending actions show "initiate drill"88892. **Execute Drill:**90 - Navigate to source servers tab in EDR Dashboard91 - Select "initiate drill" from orange dropdown menu92 - **IMPORTANT:** Do not initiate a real recovery job93 - Choose appropriate recovery point (typically most recent)94 - Click orange "initiate drill" button95963. **Monitor Drill:**97 - Observe recovery instance launch98 - Measure and document recovery time99 - Test recovered instance functionality100 - Verify data integrity1011024. **Document Results:**103 - Record recovery time104 - Compare against RTO and RPO objectives105 - Document any issues encountered106 - Note lessons learned1071085. **Clean Up:**109 - Select actions menu110 - Choose "terminate recovery instances"111 - Confirm termination112 - Verify resources are cleaned up1131146. **Review and Update:**115 - Review drill results with team116 - Update recovery procedures as needed117 - Schedule next drill118119## Default Value120121By default, no recovery drills are scheduled or configured. Organizations must manually plan and execute recovery drills.122123## References124125- [AWS Elastic Disaster Recovery - Failback Preparing](https://docs.aws.amazon.com/drs/latest/userguide/failback-preparing.html)126- [AWS DR Testing Best Practices](https://docs.aws.amazon.com/drs/latest/userguide/drill-recovery.html)127128## CIS Controls129130| Controls Version | Control | IG 1 | IG 2 | IG 3 |131| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---- | ---- | ---- |132| v8 | 11.5 Test Data Recovery<br/>Test backup recovery quarterly, or more frequently, for a sampling of in-scope enterprise assets. | | ● | ● |133| v8 | 17.7 Conduct Routine Incident Response Exercises<br/>Plan and conduct routine incident response exercises and scenarios for key personnel involved in the incident response process to prepare for responding to real-world incidents. Exercises need to test communication channels, decision making, and workflows. Conduct testing on an annual basis, at a minimum. | | ● | ● |134| v7 | 10.3 Test Data on Backup Media<br/>Test data integrity on backup media on a regular basis by performing a data restoration process to ensure that the backup is properly working. | | ● | ● |135| v7 | 19.7 Conduct Periodic Incident Scenario Sessions for Personnel<br/>Plan and conduct routine incident response exercises and scenarios for the workforce involved in the incident response to maintain awareness and comfort in responding to real world threats. Exercises should test communication channels, decision making, and incident responders technical capabilities using tools and data available to them. | | ● | ● |136137## Profile138139- Level 2
Run npx skillmds@latest add cyberstrikeus/cis-aws-storage-6-8 in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Ensure execution of a recovery drill It is listed under DevOps & Infra on SkillMD.
SkillMD's automated safety review verdict for this skill is PASS. Independent scanners report: SkillSpector: CAUTION, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
cyberstrikeus (@cyberstrikeus) published this skill. Their other Agent Skills are listed on their SkillMD profile.