Medium Transfer Regional

Transfer Family servers should not use FTP protocol for endpoint connection

NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1

Description

Flags Transfer Family servers that use FTP for endpoint connections. FTP transmits data in plaintext and should be replaced with SFTP or FTPS.


Remediation

Update the Transfer Family server configuration to use secure protocols (SFTP, FTPS, or AS2) instead of FTP.

Steps

  1. Open the AWS Transfer Family console.
  2. Select the server that is using FTP protocol.
  3. Go to the 'Protocols' section in the server settings.
  4. Remove 'FTP' from the enabled protocols.
  5. Ensure that secure protocols (SFTP, FTPS, or AS2) are enabled.
  6. Save the server configuration.

Compliance

NIST 800-53PCI DSS v4.0.1PCI DSS v4.2.1