| name | cis-aws-storage-3.7 |
| description | Ensure File-Level Access Control with Mount Targets |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","efs","mount-targets","access-control","availability-zones"] |
| cis_id | 3.7 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-3.3","cis-aws-storage-3.8"] |
| prerequisites | [] |
| severity_boost | {} |
3.7 Ensure File-Level Access Control with Mount Targets (Manual)
Profile Applicability
Description
Mount targets act as gateways, enabling resources to be accessed across different availability zones within a VPC. When you create an EFS file system, mount targets are automatically provisioned in each availability zone associated with the VPC. This ensures high availability and redundancy, allowing seamless and efficient access to the EFS file system from any availability zone.
Rationale
Using mount targets ensures seamless access to the EFS file system across different availability zones within a VPC. This automatic provisioning of mount targets in each availability zone provides high availability and redundancy, essential for maintaining uninterrupted data access. It simplifies configuration and enhances the resilience and scalability of the file system architecture.
Impact
Not using mount targets can lead to inefficient and unreliable access to the EFS file system across availability zones. This lack of automatic provisioning reduces high availability and redundancy, increasing the risk of service interruptions and data access issues. Consequently, your infrastructure may suffer from decreased performance, higher latency, and potential data loss or downtime.
Audit Procedure
Console
Verify that mount targets are properly configured in each availability zone:
- Navigate to EFS console
- Select the file system
- Verify mount targets exist in each availability zone
- Ensure mount targets are associated with appropriate subnets
Expected Result
- Mount targets should exist in each availability zone where the EFS is used
- Each mount target should be in a different availability zone for redundancy
- Mount targets should be properly associated with VPC subnets
Remediation
Console
Control access by modifying mount targets in each availability zone.
- Navigate to EFS console
- Select your file system
- Configure mount targets for each availability zone
- Ensure proper subnet association for high availability
Default Value
Mount targets are not created by default. Users must explicitly create mount targets when setting up an EFS file system.
References
- https://docs.aws.amazon.com/efs/latest/ug/accessing-fs.html
CIS Controls