This rule ensures enabling multiple availability zones for RDS DB instances.
Rule | RDS DB instance multiple az should be enabled |
Framework | Federal Financial Institutions Examination Council (FFIEC) |
Severity | ✔ Low |
Enabling Multi-AZ Deployments for RDS Instances for FFIEC Compliance
Multi-AZ (Availability Zone) deployments for Amazon Relational Database Service (RDS) instances are essential for meeting the resiliency and high availability requirements set forth by the Federal Financial Institutions Examination Council (FFIEC). Compliance with FFIEC standards implies that financial institutions must have robust disaster recovery and business continuity plans, which include maintaining high availability of critical databases.
Description of the Rule
Multi-AZ deployment involves running a primary RDS instance in one Availability Zone and maintaining a synchronous standby instance in a different, geographically distinct Availability Zone. In the event the primary RDS instance experiences a failure, RDS will automatically failover to the standby, minimizing the downtime, and ensuring continuity of operations.
Benefits of Multi-AZ
FFIEC Compliance
Troubleshooting Steps
If an RDS instance is not currently configured for Multi-AZ deployment, follow these troubleshooting steps:
Remediation Steps
To remediate and enable Multi-AZ support for an existing RDS DB instance, follow these steps:
Step-by-Step Guide
Log into the AWS Management Console: Ensure you have the necessary permissions to modify RDS instances.
Navigate to the RDS Dashboard: Click on 'Services' and then choose 'RDS' to open the RDS dashboard.
Select the DB Instance: Choose the DB instance that requires Multi-AZ enablement.
Modify the DB Instance: Click on the 'Modify' button.
Enable Multi-AZ Deployment: Scroll to the 'Multi-AZ deployment' option and select 'Yes'.
Apply Changes Immediately or During Maintenance Window: Decide whether to apply changes immediately or during your next maintenance window.
Review and Modify Additional Settings (optional): Review other settings like instance class, storage, or maintenance settings if needed.
Click on 'Continue' and 'Modify DB Instance': After reviewing the changes, click 'Continue' and then 'Modify DB Instance' to start the deployment.
AWS CLI Command
Alternatively, you can enable Multi-AZ using the AWS Command Line Interface (CLI). Here is the necessary CLI command to modify an RDS instance to become Multi-AZ:
aws rds modify-db-instance \ --db-instance-identifier <your-db-instance-identifier> \ --multi-az \ --apply-immediately
Replace
<your-db-instance-identifier>
with the actual RDS instance identifier.Considerations
By implementing Multi-AZ deployments for critical databases, financial institutions can effectively meet FFIEC guidelines, ensuring their RDS instances are resilient to failures and providing the necessary high availability for financial operations.