Skip to main content

CCC.VPC.C04: Enforce VPC Flow Logs on VPCs

Control ID:CCC.VPC.C04
Title:Enforce VPC Flow Logs on VPCs
Objective:Ensure VPCs are configured with flow logs enabled to capture traffic information.
Control Family:
Network Security

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.VPC.TH04Lack of Network Visibility due to Disabled VPC Flow LogsVPC subnets with disabled flow logs lack critical network traffic visibility, which can lead to undetected unauthorized access, data exfiltration, and network misconfigurations. This lack of visibility increases the risk of undetected security incidents.
1
1
0

Related Capabilities

IDTitleDescription
CCC.VPC.F16Flow LogsAbility to capture information about the IP traffic going through the VPC.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
PR.PT-1
0
-
ISO_27001
2013 A.12.4.1
0
-
NIST_800_53
AU-2
0
-
CCM
IVS-06
0
-

Assessment Requirements

IDDescriptionApplicability
CCC.VPC.C04.TR01When any network traffic goes to or from an interface in the VPC, the service MUST capture and log all relevant information.
tlp-amber
tlp-red