AWS DynamoDB Table Terraform module

Upstream version 5.5.2
4 controls from NIST Cybersecurity Framework v2.0 requirements

Terraform Module Source

nistcsf.compliance.tf/terraform-aws-modules/dynamodb-table/aws

Behavioral Summary

This module modifies 3 variable defaults and makes 0 resource changes from the upstream module. All changes are driven by compliance controls and can be reviewed in detail below.

Your Code Impact

If you are migrating from the upstream module, the enforced default changes mean your existing configurations will automatically gain compliance controls. Variables you have explicitly set will continue to use your values. Review the diff below to understand exactly what changes.

Compared to terraform-aws-modules/dynamodb-table/aws@5.5.23 changes

Variables Changed

3
VariableUpstreamCTFReasonControl
deletion_protection_enabled-trueThis control checks whether an Amazon DynamoDB table has deletion protection enabled. The control fails if a DynamoDB table doesn't have deletion protection enabled.dynamodb_table_deletion_protection_enabled
point_in_time_recovery_enabledfalsetrueEnable this rule to check that information has been backed up. It also maintains the backups by ensuring that point-in-time recovery is enabled in AWS DynamoDB.dynamodb_table_point_in_time_recovery_enabled
server_side_encryption_enabledfalsetrueEnsure that encryption is enabled for your AWS DynamoDB tables. Because sensitive data can exist at rest in these tables, enable encryption at rest to help protect that data.dynamodb_table_encrypted_with_kms