{
    "Behavior": "PROACTIVE",
    "ComplianceFrameworkMappings": [
        {
            "ComplianceFramework": "NIST 800-53 Rev 5",
            "Ids": [
                "CP-10",
                "CP-6(2)",
                "SC-36",
                "SC-5(2)",
                "SI-13(5)"
            ]
        }
    ],
    "ConfigRuleIdentifier": "ELASTICSEARCH_PRIMARY_NODE_FAULT_TOLERANCE",
    "ControlOwner": "AWS Control Tower",
    "DeploymentMechanism": "AWS CloudFormation Hook",
    "DeploymentOwner": "AWS Control Tower",
    "Description": "This control checks whether Elasticsearch domains are configured with at least three dedicated master nodes.",
    "DisplayName": "Require an Elasticsearch domain to have at least three dedicated master nodes",
    "DocumentationReferences": [
        {
            "DisplayName": "Sizing Amazon OpenSearch Service domains",
            "Type": "AWS Documentation",
            "Url": "https://docs.aws.amazon.com/opensearch-service/latest/developerguide/managedomains-dedicatedmasternodes.html"
        }
    ],
    "EvaluatedResourceTypes": [
        "AWS::Elasticsearch::Domain"
    ],
    "EvaluatedServices": [
        "Amazon OpenSearch Service"
    ],
    "Guidance": "Elective",
    "Id": "CT.OPENSEARCH.PR.7",
    "ImplementationType": "CloudFormation guard rule",
    "MinimumSupportedRuntimeVersion": "2.1",
    "Objectives": [
        {
            "Id": "CO.9",
            "Name": "Improve availability"
        }
    ],
    "RegionalPreference": "REGIONAL",
    "Relationships": [
        {
            "ControlId": "SH.ES.7",
            "ControlOwner": "AWS Security Hub",
            "RelationshipType": "Can be used with (Inclusive)"
        }
    ],
    "ReleaseDate": "2023-05-19",
    "RemediationMessage": "Within 'ElasticsearchClusterConfig', set 'DedicatedMasterEnabled' to 'true', and set 'DedicatedMasterCount' to an integer value greater than or equal to three, or omit the 'DedicatedMasterCount' property to adopt the default value of three.",
    "Severity": "MEDIUM",
    "SupportedRegions": [
        "af-south-1",
        "ap-east-1",
        "ap-northeast-1",
        "ap-northeast-2",
        "ap-northeast-3",
        "ap-south-1",
        "ap-south-2",
        "ap-southeast-1",
        "ap-southeast-2",
        "ap-southeast-3",
        "ap-southeast-4",
        "ca-central-1",
        "eu-central-1",
        "eu-central-2",
        "eu-north-1",
        "eu-south-1",
        "eu-south-2",
        "eu-west-1",
        "eu-west-2",
        "eu-west-3",
        "il-central-1",
        "me-central-1",
        "me-south-1",
        "sa-east-1",
        "us-east-1",
        "us-east-2",
        "us-west-1",
        "us-west-2"
    ],
    "TargetOuType": "CUSTOM",
    "Version": "1",
    "Visibility": "PUBLIC"
}