Control: 3.5 Ensure the security group are configured with fine grained rules
Description
Security groups provide stateful filtering of ingress/egress network traffic to Alibaba Cloud resources. It is recommended that all security group configured with fine grained rules.
Remediation
From Console
- Logon to ECS Console.
- In the left-side navigation pane, choose
Network & Security > Security Groups
. Remove
any unnecessary rules in all security groups.
Usage
Run the control in your terminal:
powerpipe control run alicloud_compliance.control.cis_v100_3_5
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run alicloud_compliance.control.cis_v100_3_5 --share
SQL
This control uses a named query:
select 'arn:acs:::' || account_id as resource, 'info' as status, 'Manual verification required.' as reason , account_id as account_idfrom alicloud_account;