Skip to main content

πŸ’Ό [ECS.16] ECS task sets should not automatically assign public IP addresses

  • Contextual name: πŸ’Ό [ECS.16] ECS task sets should not automatically assign public IP addresses
  • ID: /frameworks/aws-fsbp-v1.0.0/ecs/16
  • Located in: πŸ’Ό Elastic Container Service (ECS)

Description​

A public IP address is reachable from the internet. If you configure your task set with a public IP address, the resources associated with the task set can be reached from the internet. ECS task sets shouldn't be publicly accessible, as this may allow unintended access to your container application servers.

Similar​

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό PCI DSS v4.0.1 β†’ πŸ’Ό 1.4.4 System components that store cardholder data are not directly accessible from untrusted networks.3

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags