More Info:

AWS security groups configuration changes should be monitored using CloudWatch alarms.

Risk Level

Medium

Address

Security

Compliance Standards

SOC2, NIST, HIPAA, ISO27001, AWSWAF, HITRUST, CISAWS, CBP, NISTCSF

Triage and Remediation

Remediation

Sure, here are the step by step instructions to remediate the Security Group Changes Alarm misconfiguration in AWS using AWS console:

  1. Login to your AWS console.
  2. Go to the CloudWatch service.
  3. Click on “Alarms” in the left-hand menu.
  4. Select the Security Group Changes Alarm that you want to remediate.
  5. Click on “Actions” and select “Disable Alarm”.
  6. Once the alarm is disabled, you can take the necessary steps to remediate the issue that triggered the alarm.
  7. After you have remediated the issue, you can re-enable the alarm by selecting it and clicking on “Actions” and then selecting “Enable Alarm”.

It is important to note that disabling the alarm does not fix the underlying issue. You need to identify and remediate the root cause of the misconfiguration to ensure that your infrastructure remains secure.

Additional Reading: