Control: 3.2 Ensure that SSH access is restricted from the internet
Description
Security groups provide stateful filtering of ingress/egress network traffic to Alibaba Cloud resources. It is recommended that no security group allows unrestricted ingress access to port 22 or port 3389.
Remediation
From Console
- Logon to ECS Console.
- Go to
Security Group
. - Find the
Security Group
you want to modify. - Modify
Source IP
range tospecific IP
. - Click
Save
.
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v100_3_2
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v100_3_2 --share
SQL
This control uses a named query:
ecs_security_group_remote_administration