turbot/alicloud_compliance

Control: 3.2 Ensure that SSH access is restricted from the internet

Description

Security groups provide stateful filtering of ingress/egress network traffic to Alibaba Cloud resources. It is recommended that no security group allows unrestricted ingress access to port 22 or port 3389.

Remediation

From Console

  1. Logon to ECS Console.
  2. Go to Security Group.
  3. Find the Security Group you want to modify.
  4. Modify Source IP range to specific IP.
  5. Click Save.

Usage

steampipe check alicloud_compliance.control.cis_v100_3_2

SQL

This control uses a named query:

ecs_security_group_remote_administration

Tags