Skip to content

0.8.0: Address CIS-VpcDefaultSecurityGroupsMustRestrictAllTraffic (#40)

Compare
Choose a tag to compare
@goruha goruha released this 20 Aug 19:10
d16f786

What

  • Explicit declare aws_default_security_group without any security_group_rule

Why

  • Address CIS-VpcDefaultSecurityGroupsMustRestrictAllTraffic
  • If aws_default_security_group is not defined, it would be created implicitly with access 0.0.0.0/0