NET-05.1: Automation tooling remediates major network security misconfigurations commonly used in attacks. The most common example is to restrict ports 22 and 3389 if they are exposed to the internet. Despite being a common compliance requirement, these exposures frequently occur even in organizations with extensive cloud experience.
  • Control automation: Automated
  • AWS control specification: Config rules exists to automatically revert ports 22 or 3389 exposed to 0.0.0.0/0
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Pass if the CSPM automatically remediates ports 22 and 3389 open to the internet

Description

  • Control automation: Automated
  • AWS control specification: Config rules exists to automatically revert ports 22 or 3389 exposed to 0.0.0.0/0
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: Pass if the CSPM automatically remediates ports 22 and 3389 open to the internet