Risk Level: Medium (should be achieved)
Rule ID: SNS-003
Ensure that all your Amazon SNS subscriptions are periodically reviewed for appropriate subscribers and remove any unwanted subscriber in order to improve access security to your SNS topics.
This rule can help you with the following compliance standards:
- CISAWSF
- PCI
- NIST4
For further details on compliance standards supported by TrendAI Vision One™ Cloud Risk Management, see here.
Review regularly your AWS SNS subscriptions to ensure that only expected (appropriate) recipients receive the information published to your SNS topics.
Audit
To determine if there are any unwanted SNS subscribers available within your AWS account, perform the following actions:
Remediation / Resolution
To remove any unwanted SNS subscriptions from your AWS account, perform the following actions:
References
- AWS Documentation
- Amazon SNS FAQs
- What is Amazon Simple Notification Service?
- Clean Up
- AWS Command Line Interface (CLI) Documentation
- sns
- list-subscriptions
- get-subscription-attributes
- unsubscribe
Publication date Sep 29, 2017