NET-03.2: Cloud networks should minimize potential attack paths by using tightly scoped security group rules, even on non-internet facing resources.
One indicator of this is tightly scoped security groups applied to every compute resource that only allow a limited number of inbound ports (e.g., no more than five ports).
Control automation: Automated
AWS control specification: Security groups only allow a total of five ports maximum
Azure control specification: Network Security Groups allow no more than five inbound ports
Security groups are applied to all VMs/containers, not just subnets
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none
Description
Control automation: Automated
AWS control specification: Security groups only allow a total of five ports maximum
Azure control specification: Network Security Groups allow no more than five inbound ports
Security groups are applied to all VMs/containers, not just subnets
GCP control specification: none
Third-party (CSPM/CNAPP) control specification: none