Remediation
Security Group Membersβ
Perform the following to implement the prescribed state:
- Identify AWS resources that exist within the default security group.
- Create a set of least privilege security groups for those resources.
- Place the resources in those security groups.
- Remove the resources noted in #1 from the default security group.
Security Group Stateβ
-
Login to the AWS Management Console at https://console.aws.amazon.com/vpc/home.
-
Repeat the next steps for all VPCs - including the default VPC in each AWS region:
-
In the left pane, click
Security Groups
. -
For each default security group, perform the following:
- Select the
default
security group. - Click the
Inbound Rules
tab. - Remove any inbound rules.
- Click the
Outbound Rules
tab. - Remove any Outbound rules.
- Select the
Recommendedβ
IAM groups allow you to edit the name
field. After remediating default groups rules for all VPCs in all regions, edit this field to add text similar to DO NOT USE. DO NOT ADD RULES
.