More Info:

AWS VPC Customer/Internet Gateway configuration changes should be monitored using CloudWatch alarms.

Risk Level

Medium

Address

Security

Compliance Standards

SOC2, HIPAA, ISO27001, AWSWAF, HITRUST, CISAWS, CBP, NISTCSF

Triage and Remediation

Remediation

Sure, here are the step-by-step instructions to remediate the “Internet Gateway Changes Alarm” misconfiguration in AWS using the AWS console:

  1. Log in to the AWS Management Console.
  2. Navigate to the CloudWatch service.
  3. In the left-hand menu, click on “Alarms”.
  4. Locate the “Internet Gateway Changes Alarm” from the list of alarms and select it.
  5. Click on the “Actions” dropdown menu and select “Disable Alarm”.
  6. Confirm that you want to disable the alarm by clicking “Yes, Disable”.
  7. If you want to permanently remove the alarm, select the alarm again and click on the “Actions” dropdown menu and select “Delete Alarm”.
  8. Confirm that you want to delete the alarm by clicking “Yes, Delete”.

Once you have completed these steps, the “Internet Gateway Changes Alarm” will be remediated in AWS. It is important to note that disabling or deleting an alarm will prevent you from receiving notifications if the alarm is triggered in the future. Therefore, it is recommended to review the alarm settings and adjust them accordingly to avoid future misconfigurations.

Additional Reading: