High
Redshift
Regional
Redshift security groups should allow ingress on the cluster port only from restricted origins
PCI DSS v4.0.1PCI DSS v1.3.1
Description
Flags Redshift cluster security groups that allow unrestricted ingress (0.0.0.0/0 or ::/0) to the cluster port.
Remediation
Restrict Redshift cluster security group ingress to trusted sources only.
Steps
- Open the Amazon EC2 console.
- Find the security groups associated with the Redshift cluster.
- Edit inbound rules: remove any entry that allows 0.0.0.0/0 or ::/0 for the cluster port.
- Add specific CIDR ranges or security groups as needed.
Compliance
PCI DSS v4.0.1PCI DSS v1.3.1