DynamoDB table has zero read activity for 7 days
- Severity
- Medium
- Service
- DynamoDB
- Check ID
- DYNAMODB_IDLE_TABLE
What this check finds
A DynamoDB table with no consumed read capacity units over 7 days has no read traffic. If it also has no write traffic, it is completely idle. Provisioned-capacity tables in this state still incur the full provisioned-capacity charge. On-demand tables have no idle cost but may represent forgotten data that should be archived or deleted.
Passing looks like: No idle DynamoDB tables.
How to fix it
Verify whether the table is still needed. If abandoned, export the data to S3 first (aws dynamodb export-table-to-point-in-time) then delete the table: aws dynamodb delete-table --table-name TABLE_NAME. For provisioned tables still needed but rarely accessed, switch billing to on-demand: aws dynamodb update-table --table-name TABLE_NAME --billing-mode PAY_PER_REQUEST.
AWS console
DynamoDB → Tables → select → Actions → Delete table.
Compliance controls it is evidence for
A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works
| Framework | Controls |
|---|---|
| ISO/IEC 27001:2022 Annex A |
|
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs