More Info:

Your AWS CloudWatch event bus should not be exposed to everyone.

Risk Level

High

Address

Security

Compliance Standards

HITRUST, AWSWAF, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

The following are the steps to remediate the “Event Bus Should Not Be Exposed” misconfiguration on AWS using the AWS console:

  1. Log in to the AWS Management Console.
  2. Navigate to the Amazon EventBridge service.
  3. Click on the “Event buses” option on the left-hand menu.
  4. Select the event bus that is exposed.
  5. Click on the “Permissions” tab.
  6. Click on the “Edit” button to edit the permissions.
  7. Remove any unauthorized principals or accounts from the “Event bus policy” section.
  8. Click on the “Save” button to save the changes.

By following these steps, the event bus will no longer be exposed to unauthorized access and will be remediated.

Additional Reading: