Cloud
Guardrails

Data-related Guardrail Pack

Cloud Guardrails

If you're interested in contributing guidance, please start with these instructions.

Filters
Filters
Categories
Clear
Maturity Level
Clear
Functions
Clear
Cloud Provider
Clear
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
S3 bucket with lifecycle
Medium
AWS
Will Bengtson
Summary
Require lifecycle policy on S3 buckets for things like logs (1 yr deletion recommended)
Applicable to
Always
When to use/avoid
S3 bucket with replication to another account
Medium
AWS
Will Bengtson
Summary
Require replication to another account for disaster recovery
Applicable to
When effective DR is required
When to use/avoid
S3 bucket with versioning
Low
AWS
Will Bengtson
Summary
Enforce a bucket pattern with versioning to prevent malicious tampering and facilitate recovery
Applicable to
All important data
When to use/avoid
S3 bucket with replication to another account/region pair
High
AWS
Will Bengtson
Summary
Require S3 bucket replication to another account and region
Applicable to
When recovery is necessary
When to use/avoid
RDS Databases with automatic daily snapshot
Low
AWS
Will Bengtson
Summary
Configure automatic daily snapshots of RDS databases for backup purposes.
Applicable to
Always
When to use/avoid
Databackup account
Medium
AWS
Houston Hopkins
Summary
Create a Cold account for copying in data that can't be deleted.
Applicable to
Applies if you have data that has to persist for business operation, regulatory or legal reasons.
When to use/avoid
Protect against data deletion
Medium
AWS
Mark Andersen
Summary
Block delete calls on persistent data resources by default on IAM roles to avoid accidentally deleting all your data.
Applicable to
Always
When to use/avoid
DynamoDB Backup Configured
Medium
AWS
Will Bengtson
Summary
Require DynamoDB to have a backup enabled for DR.
Applicable to
To all important data in DynamoDB
When to use/avoid
Cloud Guardrails

If you're interested in contributing guidance, please start with these instructions.

Filters
Filters
Categories
Clear
Maturity Level
Clear
Functions
Clear
Cloud Provider
Clear
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Name
S3 bucket with lifecycle
Categories
Maturity Level
Medium
Functionality
Cloud Provider
Author
Will Bengtson
S3 bucket with replication to another account
Categories
Maturity Level
Medium
Functionality
Cloud Provider
Author
Will Bengtson
S3 bucket with versioning
Categories
Maturity Level
Low
Functionality
Cloud Provider
Author
Will Bengtson
S3 bucket with replication to another account/region pair
Categories
Maturity Level
High
Functionality
Cloud Provider
Author
Will Bengtson
RDS Databases with automatic daily snapshot
Categories
Maturity Level
Low
Functionality
Cloud Provider
Author
Will Bengtson
Databackup account
Categories
Maturity Level
Medium
Functionality
Cloud Provider
Author
Houston Hopkins
Protect against data deletion
Categories
Maturity Level
Medium
Functionality
Cloud Provider
Author
Mark Andersen
DynamoDB Backup Configured
Categories
Maturity Level
Medium
Functionality
Cloud Provider
Author
Will Bengtson
Process
Data
Architecture
Configuration
Change Management
Compliance
Identity
Cost Management
Reliability
Security
Standards