Network misconfigurations

ELB missing inbound rules in their security groups

Platform(s)
Compliance Frameworks

CCM-CSA, Data Security Posture Management (DSPM) Best Practices, iso_27001_2022, iso_27002_2022, Mitre ATT&CK, New Zealand Information Security Manual, NIST 800-171, NIST 800-53, Orca Best Practices, UK Cyber Essentials

Description

An Elastic Load Balancer has a security group with no inbound rules. Such a security group will prevent the load balancer from receiving any incoming traffic, regardless of the source and destination.