Skip to main content

Networking / VPC / Controls / DEV

Limit Resource Creation in Public Subnet

CCC.VPC.CN02 · Networking

Restrict the creation of resources in the public subnet with direct access to the internet to minimize attack surfaces.

Related Capabilities

IDTitleDescription
CCC.VPC.CP04Public Subnet CreationAbility to create a subnet that allows resources within the subnet to communicate with the public internet.

Related Threats

IDTitleDescription
CCC.VPC.TH02Exposure of Resources to Public InternetAssignment of external IP addresses to resources exposes resources to the public internet, increasing the risk of attacks such as brute force, exploitation of vulnerabilities, or unauthorized access.

Assessment Requirements

IDTextApplicability
CCC.VPC.CN02.AR01When a resource is created in a public subnet, that resource MUST NOT be assigned an external IP address by default.tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.AC-3
CCMSEF-05
ISO_270012013 A.13.1.1
NIST_800_53AC-4