High
RedshiftServerless
Regional
Redshift Serverless workgroups should prohibit public access
Description
Flags Amazon Redshift Serverless workgroups whose publiclyAccessible setting is true. Public workgroups receive a public IP address and are reachable from the internet, expanding the attack surface for credential and SQL-injection attacks.
Remediation
Disable public accessibility on every Redshift Serverless workgroup.
Steps
- Open the Amazon Redshift Serverless console and select the workgroup.
- Choose Edit.
- Set Publicly accessible to No.
- Save the changes.