Network misconfigurations

EKS cluster has been assigned with multiple security groups

Platform(s)
Compliance Frameworks
  • CCPA
  • ,
  • CPRA
  • ,
  • Data Security Posture Management (DSPM) Best Practices
  • ,
  • iso_27001_2022
  • ,
  • iso_27002_2022
  • ,
  • New Zealand Information Security Manual
  • ,
  • NIST 800-171
  • ,
  • NIST 800-53
  • ,
  • PDPA
  • ,
  • UK Cyber Essentials

Description

Amazon Elastic Kubernetes Service (Amazon EKS) is a managed service that you can use to run Kubernetes on AWS without needing to install, operate, and maintain your own Kubernetes control plane or nodes. Kubernetes is an open-source system for automating the deployment, scaling, and management of containerized applications. If you share a control plane security group with other Amazon EKS clusters or resources, you may block or disrupt connections to those resources. It was found the EKS Cluster {AwsEksCluster} has been assigned with multiple security groups