NET-03.1: Compute resources are placed behind a load balancer with restrictive security group rules that prevent direct attacks on the resource itself. This includes instances, VMs, containers and other similar workloads. These workloads are hosted in private subnets, when supported by the cloud provider (AWS/GCP).
  • Control automation: Automated
  • AWS control specification: * Instances and containers do not have public IP addresses, are located in a private subnet and are located behind a load balancer.
  • The load balancer does not allow more than three inbound ports
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: * Instances and containers do not have public IP addresses, are located in a private subnet and are located behind a load balancer.
  • The load balancer does not allow more than three inbound ports
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none