Skip to main content

๐Ÿ’ผ Elastic Compute Cloud (EC2)

Descriptionโ€‹

Empty...

Similarโ€‹

  • Internal
    • ID: dec-b-a355aa2e

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ [EC2.1] Amazon EBS snapshots should not be publicly restorable
๐Ÿ’ผ [EC2.2] VPC default security groups should not allow inbound or outbound traffic1
๐Ÿ’ผ [EC2.3] Attached Amazon EBS volumes should be encrypted at-rest
๐Ÿ’ผ [EC2.4] Stopped EC2 instances should be removed after a specified time period
๐Ÿ’ผ [EC2.6] VPC flow logging should be enabled in all VPCs11
๐Ÿ’ผ [EC2.7] EBS default encryption should be enabled11
๐Ÿ’ผ [EC2.8] EC2 instances should use Instance Metadata Service Version 2 (IMDSv2)11
๐Ÿ’ผ [EC2.9] Amazon EC2 instances should not have a public IPv4 address
๐Ÿ’ผ [EC2.10] Amazon EC2 should be configured to use VPC endpoints that are created for the Amazon EC2 service
๐Ÿ’ผ [EC2.15] Amazon EC2 subnets should not automatically assign public IP addresses
๐Ÿ’ผ [EC2.16] Unused Network Access Control Lists should be removed
๐Ÿ’ผ [EC2.17] Amazon EC2 instances should not use multiple ENIs
๐Ÿ’ผ [EC2.18] Security groups should only allow unrestricted incoming traffic for authorized ports
๐Ÿ’ผ [EC2.19] Security groups should not allow unrestricted access to ports with high risk10
๐Ÿ’ผ [EC2.20] Both VPN tunnels for an AWS Site-to-Site VPN connection should be up
๐Ÿ’ผ [EC2.21] Network ACLs should not allow ingress from 0.0.0.0/0 to port 22 or port 33891
๐Ÿ’ผ [EC2.23] Amazon EC2 Transit Gateways should not automatically accept VPC attachment requests
๐Ÿ’ผ [EC2.24] Amazon EC2 paravirtual instance types should not be used
๐Ÿ’ผ [EC2.25] Amazon EC2 launch templates should not assign public IPs to network interfaces
๐Ÿ’ผ [EC2.51] EC2 Client VPN endpoints should have client connection logging enabled
๐Ÿ’ผ [EC2.55] VPCs should be configured with an interface endpoint for ECR API
๐Ÿ’ผ [EC2.56] VPCs should be configured with an interface endpoint for Docker Registry
๐Ÿ’ผ [EC2.57] VPCs should be configured with an interface endpoint for Systems Manager
๐Ÿ’ผ [EC2.58] VPCs should be configured with an interface endpoint for Systems Manager Incident Manager Contacts
๐Ÿ’ผ [EC2.60] VPCs should be configured with an interface endpoint for Systems Manager Incident Manager
๐Ÿ’ผ [EC2.170] EC2 launch templates should use Instance Metadata Service Version 2 (IMDSv2)
๐Ÿ’ผ [EC2.171] EC2 VPN connections should have logging enabled
๐Ÿ’ผ [EC2.172] EC2 VPC Block Public Access settings should block internet gateway traffic