Description
Creating or deleting network ACLs, changing their entries, or changing subnet associations can alter network access. Monitor the relevant CloudTrail events to identify unintended changes.
Potential impact
Without change notifications, responding to unintended access or blocked legitimate traffic may take longer.
Remediation
Create a log metric filter for network ACL and entry creation or deletion, entry replacement, and subnet association replacement. Connect an alarm to the filter’s metric name and namespace, and configure notification recipients.
Examples
The examples correct an alarm that references a different metric from the filter. Configure log delivery and notification recipients separately.
Before
hcl
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-4.11-Changes-NACL"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = "OTHER FILTER"
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-4.11-Changes-NACL"
pattern = "{ ($.eventName = CreateNetworkAcl) || ($.eventName = CreateNetworkAclEntry) || ($.eventName = DeleteNetworkAcl) || ($.eventName = DeleteNetworkAclEntry) || ($.eventName = ReplaceNetworkAclEntry) || ($.eventName = ReplaceNetworkAclAssociation) }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-4.11-Changes-NACL"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
After
hcl
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-4.11-Changes-NACL"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = aws_cloudwatch_log_metric_filter.example.id
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-4.11-Changes-NACL"
pattern = "{ ($.eventName = CreateNetworkAcl) || ($.eventName = CreateNetworkAclEntry) || ($.eventName = DeleteNetworkAcl) || ($.eventName = DeleteNetworkAclEntry) || ($.eventName = ReplaceNetworkAclEntry) || ($.eventName = ReplaceNetworkAclAssociation) }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-4.11-Changes-NACL"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}