RDS has its scope bounded to VPC. We use a security group for database security to control the traffic.
RDS can be associated with the database (DB) security group to control open public traffic, and associated with the VPC security group when RDS is used inside the VPC and EC2 security group.
In the DB security group, you need to specify the ports, while in VPC security you need to specify the port and IPs from which traffic will come to RDS instances.
You can define the security group from your AWS VPC console and associate it while creating a DB instance: