More Info:

AWS Network ACLs configuration changes should be monitored using CloudWatch alarms.

Risk Level

Medium

Address

Security

Compliance Standards

SOC2, AWSWAF, HITRUST, CISAWS, CBP, NISTCSF

Triage and Remediation

Remediation

The “Network ACL Changes Alarm” indicates that changes have been made to the Network Access Control List (NACL) in your AWS account. To remediate this issue, you can follow the steps below:

  1. Open the AWS Management Console and navigate to the VPC service.

  2. Select the VPC where the NACL changes were made.

  3. Click on the “Network ACLs” option in the left-hand menu.

  4. Identify the NACL that has been modified and click on its name.

  5. Review the “Inbound Rules” and “Outbound Rules” tabs to identify any unauthorized changes.

  6. If unauthorized changes are identified, click the “Edit” button for the relevant rule and modify it as necessary.

  7. Click the “Save” button to apply the changes.

  8. Once all unauthorized changes have been remediated, update the alarm configuration to ensure that you are alerted if any further unauthorized changes are made to the NACL.

  9. To update the alarm configuration, navigate to the CloudWatch service, select the relevant alarm, and click the “Actions” button.

  10. Select “Edit” and update the alarm configuration as necessary.

  11. Click the “Save” button to apply the changes.

By following these steps, you can remediate the “Network ACL Changes Alarm” issue in your AWS account.

Additional Reading: