| name | cis-aws-storage-3.10 |
| description | Ensure managing AWS EFS access points |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","efs","access-points","access-control","iam"] |
| cis_id | 3.10 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-3.7","cis-aws-storage-3.11"] |
| prerequisites | [] |
| severity_boost | {} |
3.10 Ensure managing AWS EFS access points (Manual)
Profile Applicability
Description
EFS access points serve as gateways to your EFS file system, allowing applications to interact with the file system across various resources. Proper configuration of these access points within your applications is crucial to ensure seamless and secure access. By configuring EFS access points, you can control and manage which users have access to specific resources in your EFS environment, enhancing security and operational efficiency.
Rationale
The rationale behind properly configuring EFS access points is to ensure secure and efficient interaction between your applications and the EFS file system. By setting up these access points correctly, you can control and manage user permissions, ensuring that only authorized users can access specific resources. This not only enhances the security of your data but also improves operational efficiency by preventing unauthorized access and potential data breaches.
Impact
Without properly configured EFS access points, you may experience inefficient and insecure access to your EFS file system. This can lead to unauthorized users gaining access to sensitive data, resulting in potential data breaches and security vulnerabilities. Additionally, improper configuration can cause operational inefficiencies, as managing user permissions becomes more complex and error-prone, ultimately impacting the overall security and performance of your infrastructure.
Audit Procedure
Console
-
Creating an EFS access point:
You can create an EFS access point through the Amazon CLI, AWS console, and with the EFS API. An EFS can only have up to 1,000 access points.
-
Mounting an EFS access point:
Consult the section where we mounted an EFS file system on an EC2 instance. While inside the resource you want to configure an access point for, type in this command:
mount -t efs -o tls,iam,accesspoint=fsap-abcdef0123456789a fs-abc0123def456789a: /localmountpoint
-
Enforcing a User Identity with an EFS access point:
You can enforce user identity to ensure that users and groups with proper permissions are able to access the EFS system. In order to do this, you must specify the user and group ID you wish to have ownership of the files.
When enforcement is enabled, that file that is was created by the user will automatically show ownership belong to the user. When enforcement is enabled, the access point considers the User ID, group ID, and secondary group ID. It ignored the NFS client's ID.
-
Enforcing a root directory with an access point:
If you wish to override the root directory of the EFS, you can make the root directory that of the access point. To enforce the root directory with an access point, you must specify three things upon provisioning the EFS mount point: