Review unused security groups

Check actual usage and remove groups that are no longer needed.

Description

A security group that is neither attached to a resource nor referenced by other rules can add management overhead. Creating a group alone does not apply its rules to a workload.

Potential impact

Unused groups can obscure the active policy and create a mistaken impression that intended protection is already applied.

Remediation

Check resource associations and references from other security groups. Attach needed groups to the appropriate resources, and remove obsolete groups after checking their dependencies.

Examples

These excerpts show only association with an ALB. Configure the inbound and outbound rules required by the actual service separately.

Before

hcl
resource "aws_security_group" "web" {
  name        = "web-sg"
  description = "Web server security group"
  vpc_id      = aws_vpc.main.id
}

resource "aws_lb" "app" {
  name               = "app-lb"
  load_balancer_type = "application"
  subnets            = [aws_subnet.a.id, aws_subnet.b.id]
}

After

hcl
resource "aws_security_group" "web" {
  name        = "web-sg"
  description = "Web server security group"
  vpc_id      = aws_vpc.main.id
}

resource "aws_lb" "app" {
  name               = "app-lb"
  load_balancer_type = "application"
  subnets            = [aws_subnet.a.id, aws_subnet.b.id]
  security_groups    = [aws_security_group.web.id]
}

References