Skip to main content

πŸ’Ό 5.4 Ensure the default security group of every VPC restricts all traffic - Level 2 (Automated)

  • Contextual name: πŸ’Ό 5.4 Ensure the default security group of every VPC restricts all traffic - Level 2 (Automated)
  • ID: /frameworks/cis-aws-v2.0.0/05/04
  • Located in: πŸ’Ό 5 Networking

Description​

A VPC comes with a default security group whose initial settings deny all inbound traffic, allow all outbound traffic, and allow all traffic between instances assigned to the security group. If you don't specify a security group when you launch an instance, the instance is automatically assigned to this default security group. Security groups provide stateful filtering of ingress/egress network traffic to AWS resources. It is recommended that the default security group restrict all traffic.

The default VPC in every region should have its default security group updated to comply. Any newly created VPCs will automatically contain a default security group that will need remediation to comply with this recommendation.

NOTE: When implementing this recommendation, VPC flow logging is invaluable in determining the least privilege port access required by systems to work properly because it can log all packet acceptances and rejections occurring under the current security groups. This dramatically reduces the primary barrier to least privilege engineering - discovering the minimum ports required by systems in the environment. Even if the VPC flow logging recommendation in this benchmark is not adopted as a permanent security measure, it should be used during any period of discovery and engineering for least privileged security groups.

Similar​

  • Sections
    • /frameworks/cis-aws-v3.0.0/05/04
    • /frameworks/cis-aws-v1.5.0/05/04
  • Internal
    • ID: dec-c-45194107

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS AWS v1.5.0 β†’ πŸ’Ό 5.4 Ensure the default security group of every VPC restricts all traffic - Level 2 (Automated)1
πŸ’Ό CIS AWS v3.0.0 β†’ πŸ’Ό 5.4 Ensure the default security group of every VPC restricts all traffic - Level 2 (Automated)1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS AWS v1.5.0 β†’ πŸ’Ό 5.4 Ensure the default security group of every VPC restricts all traffic - Level 2 (Automated)1
πŸ’Ό CIS AWS v3.0.0 β†’ πŸ’Ό 5.4 Ensure the default security group of every VPC restricts all traffic - Level 2 (Automated)1

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (1)​

PolicyLogic CountFlags
πŸ“ AWS EC2 Default Security Group does not restrict all traffic 🟒1🟒 x6