Skip to main content

More Info:

This rule checks whether Amazon OpenSearch Service domains have fine-grained access control enabled. Fine-grained access control provides enhanced security by allowing more granular control over access to OpenSearch resources. The rule is marked as non-compliant if AdvancedSecurityOptions is not enabled for the OpenSearch Service domain.

Risk Level

Medium

Address

Security

Compliance Standards

  • APRA CPS 234 (Australia)
  • BSI C5 (Germany)
  • Brazil LGPD
  • CCPA / CPRA (California)
  • CIS Critical Security Controls v8
  • CMMC 2.0
  • CSA Cloud Controls Matrix v4
  • Cloudanix Best Practice
  • DPDPA
  • Digital Operational Resilience Act (EU)
  • Essential 8
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • KSA PDPL
  • MAS Technology Risk Management (Singapore)
  • MITRE ATT&CK (Cloud)
  • NIS2 Directive
  • NIST SP 800-171
  • NYDFS 23 NYCRR 500
  • SWIFT Customer Security Controls Framework
  • Sarbanes-Oxley IT General Controls
  • UK NCSC Cyber Assessment Framework

Triage and Remediation

Remediation

Using Console

To remediate the misconfiguration of enabling Fine-Grained Access Control on an AWS OpenSearch Service domain, you can follow these steps using the AWS Management Console:
  1. Navigate to the Amazon OpenSearch Service Console:
    • Go to the AWS Management Console (https://aws.amazon.com/console/).
    • In the “Find Services” search bar, type “OpenSearch Service” and click on it to open the OpenSearch Service console.
  2. Select the OpenSearch Service Domain:
    • In the OpenSearch dashboard, select the domain for which you want to enable Fine-Grained Access Control.
  3. Navigate to the Security Tab:
    • In the left-hand navigation pane, click on the “Configure access and resource policies” tab under the “Domain” section.
  4. Enable Fine-Grained Access Control:
    • Under the “Fine-grained access control” section, click on the “Edit” button.
  5. Configure Fine-Grained Access Control:
    • In the Fine-grained access control configuration, you can define access policies for different resources and actions.
    • Enable the Fine-Grained Access Control by toggling the switch to “Enabled”.
    • Define the access policies based on your requirements. You can set access policies for specific indices, actions, and IP addresses.
  6. Save Changes:
    • After configuring the Fine-Grained Access Control policies, click on the “Save changes” button to apply the changes to the OpenSearch Service domain.
  7. Verify the Configuration:
    • Once the changes are saved, verify that Fine-Grained Access Control is enabled by checking the settings in the Security tab of the OpenSearch Service domain.
By following these steps, you can remediate the misconfiguration of enabling Fine-Grained Access Control on an AWS OpenSearch Service domain using the AWS Management Console.

To remediate the misconfiguration of enabling Fine-Grained Access Control on an AWS OpenSearch Service domain using AWS CLI, follow these steps:
  1. Identify the OpenSearch Service Domain: Use the following AWS CLI command to list all the OpenSearch Service domains in your account:
  2. Update the Access Policy: Once you have identified the domain, you need to update the access policy to enable Fine-Grained Access Control. You can do this by creating a new access policy JSON file or updating the existing one. Here is an example of an access policy that enables Fine-Grained Access Control:
  3. Update the Access Policy: Use the following AWS CLI command to update the access policy for the OpenSearch Service domain:
  4. Verify the Configuration: Finally, verify that Fine-Grained Access Control has been successfully enabled on the OpenSearch Service domain by checking the domain configuration:
By following these steps and updating the access policy for the OpenSearch Service domain, you can remediate the misconfiguration of enabling Fine-Grained Access Control using AWS CLI.
To remediate the misconfiguration of enabling fine-grained access control for AWS OpenSearch Service domains using Python, you can follow these steps:
  1. Install the AWS SDK for Python (Boto3) if you haven’t already. You can install it using pip:
  1. Use the following Python script to enable fine-grained access control for your AWS OpenSearch Service domain:
  1. Replace the placeholders your_region, your_domain_name, and your_aws_account_id with your actual AWS region, OpenSearch Service domain name, and AWS account ID respectively.
  2. Run the Python script. After successful execution, fine-grained access control will be enabled for your AWS OpenSearch Service domain.
Please ensure that you have the necessary permissions to modify the OpenSearch Service domain configuration. You may need to run this script with an IAM user or role that has the required permissions.
Enabling advanced_security_options.enabled = true is irreversible on the domain and may change how existing clients authenticate/authorize; plan for access-policy updates before applying. terraform plan should show an in-place update of aws_opensearch_domain.THIS_DOMAIN changing advanced_security_options from enabled = false (or absent) to enabled = true with the specified master user configuration.

Additional Reading: