NET-02.1: Sensitive network ports are not exposed to the internet, including administrative ports (SSH/RDP), database ports and other common management ports. This is typically a good indicator that basic network security hygiene is in place, even if implemented manually.
  • Control automation: Automated

  • AWS control specification: Instances or load balancers are not in security groups that expose the following ports:

  • MongoDB ports 27017 and 27018

  • FTP ports 20 or 21

  • port 22

  • port 3389

  • Cassandra ports 7199 or 9160 or 8888

  • Elasticsearch/Kibana ports 9200 or 9300 or 5601

  • Kafka port 9092

  • Memcached port 11211

  • MySQL port 3306

  • Oracle ports 1521 or 2483

  • Postgres port 5432

  • Redis port 6379

  • Windows SQL Server ports 1433 or 1434

  • Telnet port 23

  • Azure control specification: VMs or load balancers are not in network security groups that expose the following ports:

  • MongoDB ports 27017 and 27018

  • FTP ports 20 or 21

  • port 22

  • port 3389

  • Cassandra ports 7199 or 9160 or 8888

  • Elasticsearch/Kibana ports 9200 or 9300 or 5601

  • Kafka port 9092

  • Memcached port 11211

  • MySQL port 3306

  • Oracle ports 1521 or 2483

  • Postgres port 5432

  • Redis port 6379

  • Windows SQL Server ports 1433 or 1434

  • Telnet port 23

  • GCP control specification: none

  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated

  • AWS control specification: Instances or load balancers are not in security groups that expose the following ports:

  • MongoDB ports 27017 and 27018

  • FTP ports 20 or 21

  • port 22

  • port 3389

  • Cassandra ports 7199 or 9160 or 8888

  • Elasticsearch/Kibana ports 9200 or 9300 or 5601

  • Kafka port 9092

  • Memcached port 11211

  • MySQL port 3306

  • Oracle ports 1521 or 2483

  • Postgres port 5432

  • Redis port 6379

  • Windows SQL Server ports 1433 or 1434

  • Telnet port 23

  • Azure control specification: VMs or load balancers are not in network security groups that expose the following ports:

  • MongoDB ports 27017 and 27018

  • FTP ports 20 or 21

  • port 22

  • port 3389

  • Cassandra ports 7199 or 9160 or 8888

  • Elasticsearch/Kibana ports 9200 or 9300 or 5601

  • Kafka port 9092

  • Memcached port 11211

  • MySQL port 3306

  • Oracle ports 1521 or 2483

  • Postgres port 5432

  • Redis port 6379

  • Windows SQL Server ports 1433 or 1434

  • Telnet port 23

  • GCP control specification: none

  • Third-party (CSPM/CNAPP) control specification: none