Backup Manual Deletion Should Be Disabled
More Info:
This rule checks if a backup vault has an attached resource-based policy which prevents deletion of recovery points. The rule is NON_COMPLIANT if the Backup Vault does not have resource-based policies or has policies without a suitable Deny statement (statement with backup:DeleteRecoveryPoint, backup:UpdateRecoveryPointLifecycle, and backup:PutBackupVaultAccessPolicy permissions).
Risk Level
High
Address
Configuration
Compliance Standards
- APRA CPS 234 (Australia)
- BSI C5 (Germany)
- Brazil LGPD
- CCPA / CPRA (California)
- CIS Critical Security Controls v8
- CMMC 2.0
- CSA Cloud Controls Matrix v4
- Cloudanix Best Practice
- DPDPA
- Digital Operational Resilience Act (EU)
- Essential 8
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- KSA PDPL
- MAS Technology Risk Management (Singapore)
- MITRE ATT&CK (Cloud)
- NIS2 Directive
- NIST SP 800-171
- NYDFS 23 NYCRR 500
- Reserve Bank of India (RBI) Master Direction – Information Technology Framework
- SWIFT Customer Security Controls Framework
- Sarbanes-Oxley IT General Controls
- UK NCSC Cyber Assessment Framework
Triage and Remediation
- Remediation
Remediation
Using Console
To remediate the issue of manual deletion of backups in AWS EC2, follow these steps using the AWS Management Console:
-
Login to AWS Console: Go to the AWS Management Console (https://console.aws.amazon.com/) and log in with your credentials.
-
Navigate to AWS Backup Service: In the AWS Management Console, search for "Backup" in the services search bar and select the "Backup" service.
-
Select Backup Vault: In the AWS Backup console, select the backup vault where your EC2 backups are stored.
-
Edit Backup Vault Settings:
- Click on the backup vault name to open the details.
- Click on the "Settings" tab.
-
Disable Manual Deletion:
- In the "Settings" tab, find the "Backup vault access policy" section.
- Click on the "Edit" button next to the "Backup vault access policy" to modify the settings.
- In the "Backup vault access policy" editor, ensure that the "Allow backup plan actions" option is selected.
- Uncheck the option that allows manual deletion of backups.
- Click on the "Save" button to apply the changes.
-
Verify Changes:
- Once you have disabled manual deletion of backups, verify the changes by navigating back to the backup vault details and checking the settings to ensure that manual deletion is disabled.
By following these steps, you have successfully remediated the issue of manual deletion of backups in AWS EC2 using the AWS Management Console.
Using CLI
To remediate the issue of backup manual deletion being enabled for AWS EC2 instances using AWS CLI, follow these steps:
- Open the AWS CLI and run the following command to describe the current backup policy for the EC2 instance:
aws backup get-backup-plan --backup-plan-id "arn:aws:backup:us-west-2:123456789012:backup-plan:1"
Replace the backup-plan-id with the actual ARN of the backup plan associated with the EC2 instance.
-
Identify the
BackupPlanNameandBackupPlanRuleassociated with the EC2 instance. -
Run the following command to update the backup plan and disable manual deletion:
aws backup update-backup-plan --backup-plan-id "arn:aws:backup:us-west-2:123456789012:backup-plan:1" --lifecycle DeleteAfterDays=30 MoveToColdStorageAfterDays=30 --backup-plan RuleName="BackupRule",TargetBackupVaultName="MyBackupVault",ScheduleExpression="cron(0 0 * * ? *)",StartWindowMinutes=60,CompletionWindowMinutes=60,RecoveryPointTags={"Key":"Environment","Value":"Production"}
Replace the backup-plan-id, DeleteAfterDays, MoveToColdStorageAfterDays, RuleName, TargetBackupVaultName, ScheduleExpression, StartWindowMinutes, CompletionWindowMinutes, and RecoveryPointTags with the appropriate values for your environment.
- Verify the update by running the following command:
aws backup get-backup-plan --backup-plan-id "arn:aws:backup:us-west-2:123456789012:backup-plan:1"
Ensure that the manual deletion is disabled in the updated backup plan.
By following these steps, you can remediate the issue of backup manual deletion being enabled for AWS EC2 instances using AWS CLI.
Using Python
To remediate the issue of Backup Manual Deletion being enabled for AWS EC2 instances using Python, you can follow these steps:
- Install the Boto3 library:
pip install boto3
- Use the following Python script to disable the manual deletion of backups for all EC2 instances in your AWS account:
import boto3
import json
def disable_manual_deletion_for_recovery_points(vault_name):
# Define the new backup vault access policy that disables manual deletion
access_policy = {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Principal": "*",
"Action": "backup:DeleteRecoveryPoint",
"Resource": "*"
}
]
}
# Convert access policy to JSON
access_policy_json = json.dumps(access_policy)
# Initialize the AWS Backup client
backup_client = boto3.client('backup')
# Update the backup vault access policy
response = backup_client.put_backup_vault_access_policy(
BackupVaultName=vault_name,
PolicyName='DenyManualDeletion',
PolicyDocument=access_policy_json
)
print(f"Manual deletion disabled for recovery points in backup vault '{vault_name}'.")
def main():
# Specify the name of the backup vault
vault_name = 'your-backup-vault-name'
# Disable manual deletion for recovery points
disable_manual_deletion_for_recovery_points(vault_name)
if __name__ == "__main__":
main()
- Run the Python script to disable manual deletion of backups for all EC2 instances in your AWS account.
This script will iterate through all EC2 instances in your AWS account and disable the manual deletion of backups for each instance. This will help prevent accidental deletion of backups for your EC2 instances.
Using Terraform
resource "aws_backup_vault" "EC2_BACKUP_VAULT" {
name = "EC2_BACKUP_VAULT_NAME" # replace with your backup vault name
}
# WARNING: This policy overwrites any existing backup vault access policy.
# Manually merge this Deny statement into your current policy before applying.
resource "aws_backup_vault_policy" "EC2_BACKUP_VAULT_POLICY" {
backup_vault_name = aws_backup_vault.EC2_BACKUP_VAULT.name
policy = jsonencode({
Version = "2012-10-17"
Statement = [
{
Effect = "Deny"
Principal = "*"
Action = [
"backup:DeleteRecoveryPoint",
"backup:UpdateRecoveryPointLifecycle",
"backup:PutBackupVaultAccessPolicy",
]
Resource = "*"
}
]
})
}
Substitute:
EC2_BACKUP_VAULT_NAMEwith the actual AWS Backup vault used for your EC2 backups.
This change does not force replacement of the backup vault, but it does fully replace any existing access policy on that vault; ensure you merge any existing statements into this policy before applying.
To verify, terraform plan should show:
aws_backup_vault_policy.EC2_BACKUP_VAULT_POLICYbeing created or updated, with apolicycontaining aDenystatement forbackup:DeleteRecoveryPoint,backup:UpdateRecoveryPointLifecycle, andbackup:PutBackupVaultAccessPolicy.