πΌ [ElastiCache.7] ElastiCache clusters should not use the default subnet group
-
Contextual name: πΌ [ElastiCache.7] ElastiCache clusters should not use the default subnet group
-
ID:
/frameworks/aws-fsbp-v1.0.0/elasticache/07
-
Located in: πΌ ElastiCache
Descriptionβ
When launching an ElastiCache cluster, a default subnet group is created if one doesn't exist already. The default group uses subnets from the default Virtual Private Cloud (VPC). We recommend using custom subnet groups that are more restrictive of the subnets that the cluster resides in, and the networking that the cluster inherits from the subnets.
Similarβ
- AWS Security Hub
- Internal
- ID:
dec-c-a2eea54e
- ID:
Similar Sections (Give Policies To)β
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ NIST SP 800-53 Revision 5 β πΌ AC-4 Information Flow Enforcement | 32 | 61 | 73 | |
πΌ NIST SP 800-53 Revision 5 β πΌ AC-4(21) Information Flow Enforcement _ Physical or Logical Separation of Information Flows | 35 | 39 | ||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-7 Boundary Protection | 29 | 5 | 33 | |
πΌ NIST SP 800-53 Revision 5 β πΌ SC-7(4) Boundary Protection _ External Telecommunications Services | 17 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-7(5) Boundary Protection _ Deny by Default β Allow by Exception | 5 | 19 | ||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-7(11) Boundary Protection _ Restrict Incoming Communications Traffic | 15 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-7(16) Boundary Protection _ Prevent Discovery of System Components | 16 | |||
πΌ NIST SP 800-53 Revision 5 β πΌ SC-7(21) Boundary Protection _ Isolation of System Components | 16 |
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|