CloudWatch alarm missing for network ACL changes

Monitor network ACL changes with a CloudWatch alarm.

Description

Creating or deleting network ACLs, changing their entries, or changing subnet associations can alter network access. Monitor the relevant CloudTrail events to identify unintended changes.

Potential impact

Without change notifications, responding to unintended access or blocked legitimate traffic may take longer.

Remediation

Create a log metric filter for network ACL and entry creation or deletion, entry replacement, and subnet association replacement. Connect an alarm to the filter’s metric name and namespace, and configure notification recipients.

Examples

The examples correct an alarm that references a different metric from the filter. Configure log delivery and notification recipients separately.

Before

hcl
resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-4.11-Changes-NACL"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = "OTHER FILTER"
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-4.11-Changes-NACL"
  pattern        = "{ ($.eventName = CreateNetworkAcl) || ($.eventName = CreateNetworkAclEntry) || ($.eventName = DeleteNetworkAcl) || ($.eventName = DeleteNetworkAclEntry) || ($.eventName = ReplaceNetworkAclEntry) || ($.eventName = ReplaceNetworkAclAssociation) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-4.11-Changes-NACL"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

After

hcl
resource "aws_cloudwatch_metric_alarm" "example" {
  alarm_name          = "CIS-4.11-Changes-NACL"
  comparison_operator = "GreaterThanOrEqualToThreshold"
  evaluation_periods  = "1"
  metric_name         = aws_cloudwatch_log_metric_filter.example.id
  namespace           = "CIS_Metric_Alarm_Namespace"
  period              = "300"
  statistic           = "Sum"
  threshold           = "1"
}

resource "aws_cloudwatch_log_metric_filter" "example" {
  name           = "CIS-4.11-Changes-NACL"
  pattern        = "{ ($.eventName = CreateNetworkAcl) || ($.eventName = CreateNetworkAclEntry) || ($.eventName = DeleteNetworkAcl) || ($.eventName = DeleteNetworkAclEntry) || ($.eventName = ReplaceNetworkAclEntry) || ($.eventName = ReplaceNetworkAclAssociation) }"
  log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name

  metric_transformation {
    name      = "CIS-4.11-Changes-NACL"
    namespace = "CIS_Metric_Alarm_Namespace"
    value     = "1"
  }
}

References