Skip to main content

💼 Public and Anonymous Access

  • Contextual name: 💼 Public and Anonymous Access
  • ID: /frameworks/cloudaware/resource-security/public-and-anonymous-access
  • Located in: 💼 Resource Security

Description

Policies for identifying, managing, and restricting access to publicly available resources.

Similar

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (79)

PolicyLogic CountFlags
📝 AWS CloudFront Web Distribution Default Root Object is not configured 🟢1🟢 x6
📝 AWS DMS Replication Instance is publicly accessible 🟢1🟢 x6
📝 AWS EBS Snapshot is publicly accessible 🟢1🟢 x6
📝 AWS EC2 Auto Scaling Group behind ELB assigns public IP to instances 🟢1🟢 x6
📝 AWS EC2 Instance with an auto-assigned public IP address is in a default subnet 🟢1🟢 x6
📝 AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports 🟢1🟢 x6
📝 AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports 🟢1🟢 x6
📝 AWS EKS Cluster allows unrestricted public traffic 🟢1🟢 x6
📝 AWS RDS Instance is publicly accessible and in an unrestricted public subnet 🟢1🟢 x6
📝 AWS RDS Snapshot is publicly accessible 🟢1🟢 x6
📝 AWS S3 Bucket is not configured to block public access 🟢1🟢 x6
📝 AWS VPC Network ACL exposes admin ports to public internet ports 🟢1🟢 x6
📝 AWS VPC Subnet Map Public IP On Launch is enabled 🟢1🟢 x6
📝 Azure Cosmos DB Account Virtual Network Filter is not enabled 🟢1🟢 x6
📝 Azure Managed Disk Public Network Access is not disabled 🟢1🟢 x6
📝 Azure Network Security Group allows public access to all ports 🟢1🟢 x6
📝 Azure Network Security Group allows public access to CIFS port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to DNS port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to FTP ports 🟢1🟢 x6
📝 Azure Network Security Group allows public access to HTTP(S) ports 🟢1🟢 x6
📝 Azure Network Security Group allows public access to MongoDB ports 🟢1🟢 x6
📝 Azure Network Security Group allows public access to MSSQL port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to MySQL port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to NetBIOS ports 🟢1🟢 x6
📝 Azure Network Security Group allows public access to Oracle DBMS ports 🟢1🟢 x6
📝 Azure Network Security Group allows public access to PostgreSQL port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to RDP port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to RPC port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to SMTP port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to SSH port 🟢1🟢 x6
📝 Azure Network Security Group allows public access to Telnet port 🟢1🟢 x6
📝 Azure Network Security Group allows public UDP access 🟢1🟢 x6
📝 Azure Public IP Address is not associated with any resource 🟢1🟢 x6
📝 Azure Public IP Addresses are not evaluated periodically 🟢🟢 x3
📝 Azure SQL Database allows ingress from 0.0.0.0/0 (ANY IP) 🟢1🟢 x6
📝 Azure SQL Server Public Network Access is not disabled 🟢1🟢 x6
📝 Azure Storage Account Allow Blob Anonymous Access is enabled 🟢1🟢 x6
📝 Azure Storage Account Default Network Access Rule is not set to Deny 🟢1🟢 x6
📝 Azure Storage Account Public Network Access is not disabled 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to all ports 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to CIFS port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to DNS port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to FTP ports 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to HTTP(S) ports 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to MongoDB ports 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to MSSQL port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to MySQL port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to NetBIOS ports 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to Oracle DBMS ports 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to PostgreSQL port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to RDP port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to RPC port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to SMTP port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to SSH port 🟢1🟢 x6
📝 Azure Virtual Machine allows public access to Telnet port 🟢1🟢 x6
📝 Azure Virtual Machine allows public UDP access 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to all ports 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to CIFS port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to DNS port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to FTP ports 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to HTTP(S) ports 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to MongoDB ports 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to MSSQL port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to MySQL port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to NetBIOS ports 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to Oracle DBMS ports 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to PostgreSQL port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to RDP port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to RPC port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to SMTP port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to SSH port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public access to Telnet port 🟢1🟢 x6
📝 Azure VM Scale Set Instance allows public UDP access 🟢1🟢 x6
📝 Google BigQuery Dataset is anonymously or publicly accessible 🟢1🟢 x6
📝 Google Cloud SQL Instance External Authorized Networks do not whitelist all public IP addresses 🟢1🟢 x6
📝 Google Cloud SQL Instance has public IP addresses 🟢1🟢 x6
📝 Google GCE Instance has a public IP address 🟢1🟢 x6
📝 Google KMS Crypto Key is anonymously or publicly accessible 🟠🟢🟠 x1, 🟢 x3
📝 Google Storage Bucket is anonymously or publicly accessible 🟢1🟢 x6