Skip to main content

💼 1.3.2 Limit inbound Internet traffic to IP addresses within the DMZ.

  • ID: /frameworks/pci-dss-v3.2.1/01/03/02

Stats​

not available

Description​

Empty...

Similar​

  • Sections
    • /frameworks/pci-dss-v4.0/01/04/02
    • /frameworks/aws-fsbp-v1.0.0/dms/01
    • /frameworks/aws-fsbp-v1.0.0/emr/01
    • /frameworks/aws-fsbp-v1.0.0/es/02
    • /frameworks/aws-fsbp-v1.0.0/lambda/01
    • /frameworks/aws-fsbp-v1.0.0/opensearch/02
    • /frameworks/aws-fsbp-v1.0.0/rds/02
    • /frameworks/aws-fsbp-v1.0.0/redshift/01
    • /frameworks/aws-fsbp-v1.0.0/s3/01
    • /frameworks/aws-fsbp-v1.0.0/s3/02
    • /frameworks/aws-fsbp-v1.0.0/s3/03
    • /frameworks/aws-fsbp-v1.0.0/sagemaker/01
  • Internal
    • ID: dec-c-894c10bb

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [DMS.1] Database Migration Service replication instances should not be public11no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [EMR.1] Amazon EMR cluster primary nodes should not have public IP addressesno data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [ES.2] Elasticsearch domains should not be publicly accessible1no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [Lambda.1] Lambda function policies should prohibit public access1no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [Opensearch.2] OpenSearch domains should not be publicly accessible1no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [RDS.2] RDS DB Instances should prohibit public access, as determined by the PubliclyAccessible configuration11no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [Redshift.1] Amazon Redshift clusters should prohibit public access1no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [S3.1] S3 general purpose buckets should have block public access settings enabled1no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [S3.2] S3 general purpose buckets should block public read access2no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [S3.3] S3 general purpose buckets should block public write access2no data
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [SageMaker.1] Amazon SageMaker AI notebook instances should not have direct internet access1no data
💼 PCI DSS v4.0 → 💼 1.4.2 Inbound traffic from untrusted networks to trusted networks is restricted.31100no data

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 PCI DSS v4.0 → 💼 1.4.2 Inbound traffic from untrusted networks to trusted networks is restricted.31100no data

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (100)​

PolicyLogic CountFlagsCompliance
🛡️ AWS DMS Replication Instance is publicly accessible🟢1🟢 x6no data
🛡️ AWS EBS Snapshot is publicly accessible🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted DNS traffic🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted FTP traffic🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted NetBIOS traffic🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted RPC traffic🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted SMTP traffic🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted traffic to MongoDB🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted traffic to MSSQL🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted traffic to MySQL🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted traffic to Oracle DBMS🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted traffic to PostgreSQL🟢1🟢 x6no data
🛡️ AWS EC2 Security Group allows unrestricted Telnet traffic🟢1🟢 x6no data
🛡️ AWS Lambda Function allows public access🟢1🟢 x6no data
🛡️ AWS Lambda Function is not in a VPC🟢1🟢 x6no data
🛡️ AWS OpenSearch Domain has a public endpoint🟢1🟢 x6no data
🛡️ AWS OpenSearch Domain is not encrypted at rest🟢1🟢 x6no data
🛡️ AWS RDS Instance is publicly accessible🟢1🟢 x6no data
🛡️ AWS RDS Snapshot is publicly accessible🟢1🟢 x6no data
🛡️ AWS Redshift Cluster is publicly accessible🟢1🟢 x6no data
🛡️ AWS S3 Bucket ACL allows public read or write access🟢1🟢 x6no data
🛡️ AWS S3 Bucket is not configured to block public access🟢1🟢 x6no data
🛡️ AWS S3 Bucket Policy allows public read or write access🟢1🟢 x6no data
🛡️ AWS SageMaker Notebook Instance Direct Internet Access is not disabled🟢1🟢 x6no data
🛡️ Azure Cosmos DB Account Virtual Network Filter is not enabled🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to CIFS port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to DNS port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to FTP ports🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to HTTP(S) ports🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to MongoDB ports🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to MSSQL port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to MySQL port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to NetBIOS ports🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to Oracle DBMS ports🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to PostgreSQL port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to RDP port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to RPC port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to SMTP port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to SSH port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public access to Telnet port🟢1🟢 x6no data
🛡️ Azure Network Security Group allows public UDP access🟢1🟢 x6no data
🛡️ Azure SQL Database allows ingress from 0.0.0.0/0 (ANY IP)🟢1🟢 x6no data
🛡️ Azure Storage Account Allow Blob Anonymous Access is enabled🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to CIFS port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to DNS port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to FTP ports🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to HTTP(S) ports🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to MongoDB ports🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to MSSQL port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to MySQL port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to NetBIOS ports🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to Oracle DBMS ports🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to PostgreSQL port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to RDP port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to RPC port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to SMTP port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to SSH port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public access to Telnet port🟢1🟢 x6no data
🛡️ Azure Virtual Machine allows public UDP access🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to CIFS port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to DNS port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to FTP ports🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to HTTP(S) ports🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to MongoDB ports🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to MSSQL port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to MySQL port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to NetBIOS ports🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to Oracle DBMS ports🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to PostgreSQL port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to RDP port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to RPC port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to SMTP port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to SSH port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public access to Telnet port🟢1🟢 x6no data
🛡️ Azure VM Scale Set Instance allows public UDP access🟢1🟢 x6no data
🛡️ Google Cloud DNS Managed Zone DNSSEC is not enabled🟢1🟢 x6no data
🛡️ Google Cloud DNS Managed Zone DNSSEC Key-Signing Algorithm is RSASHA1🟢1🟢 x6no data
🛡️ Google Cloud DNS Managed Zone DNSSEC Zone-Signing Algorithm is RSASHA1🟢1🟢 x6no data
🛡️ Google Cloud SQL Instance has public IP addresses🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted DNS traffic🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted FTP traffic🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted HTTP traffic🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted NetBIOS traffic🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted RDP traffic🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted SMTP traffic🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted SSH traffic🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted traffic to Directory services"🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted traffic to MongoDB🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted traffic to MySQL🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted traffic to OracleDB🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted traffic to PostgreSQL🟢1🟢 x6no data
🛡️ Google GCE Network allows unrestricted Telnet traffic🟢1🟢 x6no data
🛡️ Google GKE Cluster Control Plane Authorized Networks are disabled🟢1🟢 x6no data
🛡️ Google Project has a default network🟢1🟢 x6no data
🛡️ Google Project has a legacy network🟢1🟢 x6no data
🛡️ Google Storage Bucket is anonymously or publicly accessible🟢1🟢 x6no data
🛡️ Oracle IAAS Security List allows unrestricted RDP traffic🟢1🟢 x6no data
🛡️ Oracle IAAS Security List allows unrestricted SSH traffic🟢1🟢 x6no data