Control: 2.11 Ensure instances stopped for over 90 days are removed
Description
Enable this rule to help with the baseline configuration of Amazon Elastic Compute Cloud (Amazon EC2) instances by checking whether Amazon EC2 instances have been stopped for more than the allowed number of days, according to your organization’s standards.
Remediation
From the Console:
- Login to the EC2 console at https://console.aws.amazon.com/ec2/.
- In the left pane, click
Instances
, clickInstances
. - Select the Instance for that hasn't been used for over 90 days.
- Under the
Details
tab. - Click
Instance state
, clickTerminate instance
. - Click
Terminate
. - Repeat steps no. 3 – 6 the other instances with a launch date equal to or over 90 days.
Repeat all steps for the other regions.
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.cis_compute_service_v100_2_11
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.cis_compute_service_v100_2_11 --share
SQL
This control uses a named query:
ec2_stopped_instance_90_days