NET-03.2: Cloud networks should minimize potential attack paths by using tightly scoped security group rules, even on non-internet facing resources. One indicator of this is tightly scoped security groups applied to every compute resource that only allow a limited number of inbound ports (e.g., no more than five ports).
  • Control automation: Automated
  • AWS control specification: Security groups only allow a total of five ports maximum
  • Azure control specification: Network Security Groups allow no more than five inbound ports

Security groups are applied to all VMs/containers, not just subnets

  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: Security groups only allow a total of five ports maximum
  • Azure control specification: Network Security Groups allow no more than five inbound ports

Security groups are applied to all VMs/containers, not just subnets

  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none