WKL-05.1: Instances/VMs are predominantly autoscaled and even most longer-running workloads are in autoscale groups for resiliency. SSH/RDP is disabled for these workloads, which indicates a higher maturity because any issues are managed in the pipeline/image creation and this reduces attack surface.
  • Control automation: Automated
  • AWS control specification: * Instances are in the account
  • 90% of instances are in autoscale groups
  • Ports 22 and 3389 are not enabled for any security group associated with an autoscaled instance (Note: Autoscaling may be quickly detectable by looking for the standard AWS tag with the autoscale group name aws:autoscaling:groupName)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: * Instances are in the account
  • 90% of instances are in autoscale groups
  • Ports 22 and 3389 are not enabled for any security group associated with an autoscaled instance (Note: Autoscaling may be quickly detectable by looking for the standard AWS tag with the autoscale group name aws:autoscaling:groupName)
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none