Ensure that the access to your Amazon OpenSearch domains is made through approved IP addresses only in order to protect domains against unauthorized access. Before running this rule by the Trend Micro Cloud One™ – Conformity engine, the list with the approved IP addresses/IP ranges must be configured in the rule settings, on your Conformity account console.
This rule can help you with the following compliance standards:
- PCI
- APRA
- MAS
- NIST4
For further details on compliance standards supported by Conformity, see here.
This rule resolution is part of the Conformity Security & Compliance tool for AWS.
Using OpenSearch IP-based access policies will allow only specific IP addresses or IP address ranges to access your Amazon OpenSearch domain endpoints, acting as a firewall that prevents incoming anonymous or unauthorized requests from reaching your OpenSearch domains (clusters).
Audit
To determine if your OpenSearch domains are using IP-based access policies, perform the following operations:
Remediation / Resolution
To implement an IP-based access policy for your Amazon OpenSearch domains, perform the following operations:
References
- AWS Documentation
- Amazon OpenSearch Service FAQs
- Creating and managing Amazon OpenSearch Service domains
- What is Amazon OpenSearch Service?
- AWS Command Line Interface (CLI) Documentation
- es
- list-domain-names
- describe-elasticsearch-domain
- update-elasticsearch-domain-config
- CloudFormation Documentation
- Amazon OpenSearch Service (successor to Amazon Elasticsearch Service) resource type reference
- Terraform Documentation
- AWS Provider
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
OpenSearch Accessible Only From Safelisted IP Addresses
Risk Level: High