NET-05.1: Automation tooling remediates major network security misconfigurations commonly used in attacks. The most common example is to restrict ports 22 and 3389 if they are exposed to the internet. Despite being a common compliance requirement, these exposures frequently occur even in organizations with extensive cloud experience.
Control automation: Automated
AWS control specification: Config rules exists to automatically revert ports 22 or 3389 exposed to 0.0.0.0/0
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: Pass if the CSPM automatically remediates ports 22 and 3389 open to the internet
Description
Control automation: Automated
AWS control specification: Config rules exists to automatically revert ports 22 or 3389 exposed to 0.0.0.0/0
Azure control specification: none
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: Pass if the CSPM automatically remediates ports 22 and 3389 open to the internet