Ensure that all your Amazon OpenSearch domains are configured to allow access only to trusted AWS accounts in order to protect against unauthorized cross-account access. Before running this rule by the Trend Micro Cloud One™ – Conformity engine, the list with the trusted AWS account identifiers must be configured in the rule settings, on your Conformity account console.
This rule can help you with the following compliance standards:
- PCI
- APRA
- MAS
- NIST4
For further details on compliance standards supported by Conformity, see here.
This rule can help you work with the AWS Well-Architected Framework.
This rule resolution is part of the Conformity Security & Compliance tool for AWS.
Allowing unknown (unauthorized) AWS accounts to access your Amazon OpenSearch domains can lead to unauthorized actions such as uploading, downloading, and deleting documents without permission. To prevent any unauthorized actions performed on your OpenSearch domains, restrict access only to trusted entities by implementing the appropriate access policies.
Audit
To determine if there are any Amazon OpenSearch domains that allow unknown cross-account access within your AWS account, perform the following actions:
Remediation / Resolution
To update your Amazon OpenSearch domain access policy in order to allow cross-account access to trusted AWS identities only, perform the following operations:
References
- AWS Documentation
- Creating and managing Amazon OpenSearch Service domains
- What is Amazon OpenSearch Service?
- AWS Policy Generator
- AWS Command Line Interface (CLI) Documentation
- es
- list-domain-names
- describe-elasticsearch-domain
- update-elasticsearch-domain-config
- CloudFormation Documentation
- Amazon OpenSearch Service (successor to Amazon Elasticsearch Service) resource type reference
- Terraform Documentation
- AWS Provider
Unlock the Remediation Steps
Free 30-day Trial
Automatically audit your configurations with Conformity
and gain access to our cloud security platform.
You are auditing:
OpenSearch Cross Account Access
Risk Level: Very High