Skip to main content

πŸ’Ό [EC2.4] Stopped EC2 instances should be removed after a specified time period

  • Contextual name: πŸ’Ό [EC2.4] Stopped EC2 instances should be removed after a specified time period
  • ID: /frameworks/aws-fsbp-v1.0.0/ec2/04
  • Located in: πŸ’Ό Elastic Compute Cloud (EC2)

Description​

When an EC2 instance has not run for a significant period of time, it creates a security risk because the instance is not being actively maintained (analyzed, patched, updated). If it is later launched, the lack of proper maintenance could result in unexpected issues in your AWS environment. To safely maintain an EC2 instance over time in an inactive state, start it periodically for maintenance and then stop it after maintenance. Ideally, this should be an automated process.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-9(1) Internal System Connections _ Compliance Checks15
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration713
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2(2) Baseline Configuration _ Automation Support for Accuracy and Currency13

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags