turbot/alicloud_compliance

Control: 4.4 Ensure no security groups allow ingress from 0.0.0.0/0 to port 3389

Description

Security groups provide filtering of ingress/egress network traffic to Aliyun resources. It is recommended that no security group allows unrestricted ingress access to port 3389.

Remediation

From Console

  1. Logon to ECS Console.
  2. In the left pane, click to expand Network and Security, click Security Groups

For each security group, perform the following:

  1. Select the security group.
  2. Click Add Rules.
  3. Click the Inbound tab.
  4. Identify the rules to be removed.
  5. Click Delete in the Remove column.
  6. Click OK.

Usage

steampipe check alicloud_compliance.control.cis_v100_4_4

SQL

This control uses a named query:

ecs_security_group_restrict_ingress_rdp_all

Tags