π‘οΈ AWS OpenSearch Domain latest Service Software Update is not installedπ’
- Contextual name: π‘οΈ Domain latest Service Software Update is not installedπ’
- ID:
/ce/ca/aws/opensearch/domain-software-update - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
RELIABILITY
Logicβ
- π§ prod.logic.yamlπ’
Similar Policiesβ
- AWS Security Hub: [Opensearch.10] OpenSearch domains should have the latest software update installed
Descriptionβ
Descriptionβ
This policy identifies AWS OpenSearch Domains that are not configured to run the latest compatible service software version. Service software updates include essential security patches, bug fixes, and performance enhancements that help maintain a secure, reliable, and optimized OpenSearch environment.
Rationaleβ
Applying the latest service software updates on a regular basis helps safeguard OpenSearch domains against known vulnerabilities, improves stability by resolving bugs, and provides access to new features and performance improvements.
Impactβ
Failing to install the latest updates can expose OpenSearch domains to security risks, reduce performance efficiency, and cause operational instability due to unresolved defects. Additionally, outdated domains may lack access to new capabilities that enhance functionality and reliability.
Auditβ
This policy flags an AWS OpenSearch Domain as
INCOMPLIANTifService Software: Update Availablefield is set to false.
Remediationβ
Remediationβ
Start Service Software Updateβ
From AWS CLIβ
Use the following command to initiate a service software update for an OpenSearch domain:
aws opensearch start-service-software-update \
--domain-name {{domain-name}} \
--schedule-at "NOW"The
--schedule-atparameter allows you to queue the update immediately.If the command fails with a
BaseException, the specified time slot may be unavailable due to capacity constraints. In such cases, review the alternate time slot suggestions provided in the response and resubmit the request with an available time.
policy.yamlβ
Linked Framework Sectionsβ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| πΌ AWS Well-Architected β πΌ SEC06-BP01 Perform vulnerability management | 2 | no data | |||
| πΌ Cloudaware Framework β πΌ Infrastructure Modernization | 17 | no data |