Skip to main content

Review

Review the EC2 security group and confirm how it was created and managed.

Validate whether the security group is associated with a CloudFormation stack, Amazon EKS cluster, Service Catalog provisioned product, AWS Application Migration Service workflow, AWS Elastic Disaster Recovery workflow, Elastic Beanstalk environment, another automation workflow, or a manual process. If the creation source is known, document the ownership and lifecycle expectations. If the security group is no longer needed, remove it through the appropriate operational process.