Auto Scaling Group Launch Configuration Has Public IP Address
Overview
This control checks whether an Auto Scaling group's associated launch configuration assigns a public IP address to the group's instances. Amazon EC2 instances in an Auto Scaling group launch configuration should not have an associated public IP address, except for in limited cases. Amazon EC2 instances should only be accessible from behind a load balancer instead of being directly exposed to the internet.
Vendor
AWS
Cloud Service
Auto Scaling
Related Controls
Autoscaling.5
References
https://docs.aws.amazon.com/securityhub/latest/userguide/autoscaling-controls.html#autoscaling-5
Severity
4
Item Types
AWS::AutoScaling::LaunchConfiguration