AWS Security ChangesHomeSearch

AWS securityhub high security documentation change

Service: securityhub · 2026-04-25 · Security-related high

File: securityhub/latest/userguide/rds-controls.md

Summary

Added new control [RDS.51] 'RDS global clusters should run on a supported Aurora MySQL version' to the list of RDS controls and added detailed documentation for this control including category, severity, resource type, AWS Config rule, parameters, and remediation guidance.

Security assessment

This change adds a new security control that specifically addresses vulnerability management by ensuring Aurora MySQL global clusters run on supported versions with security patches. The documentation explicitly states that running unsupported versions 'can expose your global database to security vulnerabilities' and references security patches, bug fixes, and performance improvements. The control is categorized under 'Identify > Vulnerability, patch, and version management' with 'High' severity, indicating it addresses a significant security concern.

Diff

diff --git a/securityhub/latest/userguide/rds-controls.md b/securityhub/latest/userguide/rds-controls.md
index 865ed4df5..03f90f1fc 100644
--- a//securityhub/latest/userguide/rds-controls.md
+++ b//securityhub/latest/userguide/rds-controls.md
@@ -7 +7 @@
-[RDS.1] RDS snapshot should be private[RDS.2] RDS DB Instances should prohibit public access, as determined by the PubliclyAccessible configuration[RDS.3] RDS DB instances should have encryption at-rest enabled[RDS.4] RDS cluster snapshots and database snapshots should be encrypted at rest[RDS.5] RDS DB instances should be configured with multiple Availability Zones[RDS.6] Enhanced monitoring should be configured for RDS DB instances[RDS.7] RDS clusters should have deletion protection enabled[RDS.8] RDS DB instances should have deletion protection enabled[RDS.9] RDS DB instances should publish logs to CloudWatch Logs[RDS.10] IAM authentication should be configured for RDS instances[RDS.11] RDS instances should have automatic backups enabled[RDS.12] IAM authentication should be configured for RDS clusters[RDS.13] RDS automatic minor version upgrades should be enabled[RDS.14] Amazon Aurora clusters should have backtracking enabled[RDS.15] RDS DB clusters should be configured for multiple Availability Zones[RDS.16] Aurora DB clusters should be configured to copy tags to DB snapshots[RDS.17] RDS DB instances should be configured to copy tags to snapshots[RDS.18] RDS instances should be deployed in a VPC[RDS.19] Existing RDS event notification subscriptions should be configured for critical cluster events[RDS.20] Existing RDS event notification subscriptions should be configured for critical database instance events[RDS.21] An RDS event notifications subscription should be configured for critical database parameter group events[RDS.22] An RDS event notifications subscription should be configured for critical database security group events[RDS.23] RDS instances should not use a database engine default port[RDS.24] RDS Database clusters should use a custom administrator username[RDS.25] RDS database instances should use a custom administrator username[RDS.26] RDS DB instances should be protected by a backup plan[RDS.27] RDS DB clusters should be encrypted at rest[RDS.28] RDS DB clusters should be tagged[RDS.29] RDS DB cluster snapshots should be tagged[RDS.30] RDS DB instances should be tagged[RDS.31] RDS DB security groups should be tagged[RDS.32] RDS DB snapshots should be tagged[RDS.33] RDS DB subnet groups should be tagged[RDS.34] Aurora MySQL DB clusters should publish audit logs to CloudWatch Logs[RDS.35] RDS DB clusters should have automatic minor version upgrade enabled[RDS.36] RDS for PostgreSQL DB instances should publish logs to CloudWatch Logs[RDS.37] Aurora PostgreSQL DB clusters should publish logs to CloudWatch Logs[RDS.38] RDS for PostgreSQL DB instances should be encrypted in transit[RDS.39] RDS for MySQL DB instances should be encrypted in transit[RDS.40] RDS for SQL Server DB instances should publish logs to CloudWatch Logs[RDS.41] RDS for SQL Server DB instances should be encrypted in transit[RDS.42] RDS for MariaDB DB instances should publish logs to CloudWatch Logs[RDS.43] RDS DB proxies should require TLS encryption for connections[RDS.44] RDS for MariaDB DB instances should be encrypted in transit[RDS.45] Aurora MySQL DB clusters should have audit logging enabled[RDS.46] RDS DB instances should not be deployed in public subnets with routes to internet gateways[RDS.47] RDS for PostgreSQL DB clusters should be configured to copy tags to DB snapshots[RDS.48] RDS for MySQL DB clusters should be configured to copy tags to DB snapshots[RDS.50] RDS DB clusters should have enough backup retention period set
+[RDS.1] RDS snapshot should be private[RDS.2] RDS DB Instances should prohibit public access, as determined by the PubliclyAccessible configuration[RDS.3] RDS DB instances should have encryption at-rest enabled[RDS.4] RDS cluster snapshots and database snapshots should be encrypted at rest[RDS.5] RDS DB instances should be configured with multiple Availability Zones[RDS.6] Enhanced monitoring should be configured for RDS DB instances[RDS.7] RDS clusters should have deletion protection enabled[RDS.8] RDS DB instances should have deletion protection enabled[RDS.9] RDS DB instances should publish logs to CloudWatch Logs[RDS.10] IAM authentication should be configured for RDS instances[RDS.11] RDS instances should have automatic backups enabled[RDS.12] IAM authentication should be configured for RDS clusters[RDS.13] RDS automatic minor version upgrades should be enabled[RDS.14] Amazon Aurora clusters should have backtracking enabled[RDS.15] RDS DB clusters should be configured for multiple Availability Zones[RDS.16] Aurora DB clusters should be configured to copy tags to DB snapshots[RDS.17] RDS DB instances should be configured to copy tags to snapshots[RDS.18] RDS instances should be deployed in a VPC[RDS.19] Existing RDS event notification subscriptions should be configured for critical cluster events[RDS.20] Existing RDS event notification subscriptions should be configured for critical database instance events[RDS.21] An RDS event notifications subscription should be configured for critical database parameter group events[RDS.22] An RDS event notifications subscription should be configured for critical database security group events[RDS.23] RDS instances should not use a database engine default port[RDS.24] RDS Database clusters should use a custom administrator username[RDS.25] RDS database instances should use a custom administrator username[RDS.26] RDS DB instances should be protected by a backup plan[RDS.27] RDS DB clusters should be encrypted at rest[RDS.28] RDS DB clusters should be tagged[RDS.29] RDS DB cluster snapshots should be tagged[RDS.30] RDS DB instances should be tagged[RDS.31] RDS DB security groups should be tagged[RDS.32] RDS DB snapshots should be tagged[RDS.33] RDS DB subnet groups should be tagged[RDS.34] Aurora MySQL DB clusters should publish audit logs to CloudWatch Logs[RDS.35] RDS DB clusters should have automatic minor version upgrade enabled[RDS.36] RDS for PostgreSQL DB instances should publish logs to CloudWatch Logs[RDS.37] Aurora PostgreSQL DB clusters should publish logs to CloudWatch Logs[RDS.38] RDS for PostgreSQL DB instances should be encrypted in transit[RDS.39] RDS for MySQL DB instances should be encrypted in transit[RDS.40] RDS for SQL Server DB instances should publish logs to CloudWatch Logs[RDS.41] RDS for SQL Server DB instances should be encrypted in transit[RDS.42] RDS for MariaDB DB instances should publish logs to CloudWatch Logs[RDS.43] RDS DB proxies should require TLS encryption for connections[RDS.44] RDS for MariaDB DB instances should be encrypted in transit[RDS.45] Aurora MySQL DB clusters should have audit logging enabled[RDS.46] RDS DB instances should not be deployed in public subnets with routes to internet gateways[RDS.47] RDS for PostgreSQL DB clusters should be configured to copy tags to DB snapshots[RDS.48] RDS for MySQL DB clusters should be configured to copy tags to DB snapshots[RDS.50] RDS DB clusters should have enough backup retention period set[RDS.51] RDS global clusters should run on a supported Aurora MySQL version
@@ -1362,0 +1363,29 @@ To configure the backup retention period for an RDS DB cluster, modify the clust
+## [RDS.51] RDS global clusters should run on a supported Aurora MySQL version
+
+**Category:** Identify > Vulnerability, patch, and version management
+
+**Severity:** High
+
+**Resource type:** `AWS::RDS::GlobalCluster`
+
+**AWS Config rule:** [rds-global-cluster-aurora-mysql-supported-version](https://docs.aws.amazon.com/config/latest/developerguide/rds-global-cluster-aurora-mysql-supported-version.html)
+
+**Schedule type:** Change triggered
+
+**Parameters:**
+
+  * `minSupportedEngineVersion`: `8.0.mysql_aurora.3.08.0` (not customizable)
+
+  * `longTermSupportVersion`: `8.0.mysql_aurora.3.04.0, 8.0.mysql_aurora.3.04.1, 8.0.mysql_aurora.3.04.2, 8.0.mysql_aurora.3.04.3` (not customizable)
+
+
+
+
+This control checks whether an Amazon Aurora MySQL global cluster is running on a minimum supported engine version. The control fails if the Aurora MySQL global cluster engine version is below the specified minimum supported version and is not listed in the long-term support version parameter.
+
+Running Aurora MySQL global databases on supported engine versions helps ensure that you have access to the latest security patches, bug fixes, and performance improvements. Aurora MySQL minor versions have defined end-of-standard-support dates, after which they no longer receive critical patches. Running an unsupported version can expose your global database to security vulnerabilities and may result in Amazon RDS Extended Support charges. Because Aurora MySQL follows a non-contiguous support lifecycle where long-term support (LTS) versions remain supported longer than subsequent non-LTS versions, this control also checks for LTS versions that are still under standard support. For more information, see [Release calendars for Amazon Aurora MySQL](https://docs.aws.amazon.com/AmazonRDS/latest/AuroraMySQLReleaseNotes/AuroraMySQL.release-calendars.html) in the _Amazon Aurora Release Notes for Aurora MySQL_.
+
+### Remediation
+
+For information about upgrading an Aurora MySQL global database to a supported engine version, see [Upgrading an Amazon Aurora global database](https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-global-database-upgrade.html) and [Upgrading Aurora MySQL by modifying the engine version](https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/AuroraMySQL.Updates.Patching.html) in the _Amazon Aurora User Guide_.
+