turbot/alicloud_compliance

Control: 3.3 Ensure VPC flow logging is enabled in all VPCs

Description

You can use the flow log function to monitor the IP traffic information for an ENI, a VSwitch or a VPC. If you create a flow log for a VSwitch or a VPC, all the Elastic Network Interfaces, including the newly created Elastic Network Interfaces, are monitored. Such flow log data is stored in Log Service, where you can view and analyze IP traffic information. It is recommended that VPC Flow Logs be enabled for packet "Rejects" for VPCs.

Remediation

From Console

  1. Logon to VPC console.
  2. In the left-side navigation pane, click FlowLog.
  3. Follow the instruction to create FlowLog for each of your VPCs.

Usage

Run the control in your terminal:

powerpipe control run alicloud_compliance.control.cis_v100_3_3

Snapshot and share results via Turbot Pipes:

powerpipe login
powerpipe control run alicloud_compliance.control.cis_v100_3_3 --share

SQL

This control uses a named query:

manual_control

Tags