Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-database-7-2명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | cis-aws-database-7.2 |
| description | Ensure VPC Security is Configured |
| category | cis-database |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","database","documentdb","vpc","security-groups","subnets"] |
| cis_id | 7.2 |
| cis_benchmark | CIS AWS Database Services Benchmark v2.0.0 |
| tech_stack |
| ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-database-7.1","cis-aws-database-7.3","cis-aws-database-7.5"] |
| prerequisites | [] |
| severity_boost | {} |
Creating a VPC, configuring subnets, and creating security groups help isolate your DocumentDB instances within your virtual network and control inbound and outbound traffic.
Setting up a Virtual Private Cloud (VPC) protects the private network that has been established from any external networks from interfering. It allows internal networks to communicate with one another with the network that has been established.
Builds a strong connection between internal networks, has a strong connection with the internet, and it secures your data from getting into the hands of an unauthorized party.
Sign into the AWS Management Console
Open the Amazon VPC Console
Find Services search bar or by directly accessing the console at https://console.aws.amazon.com/vpc/.Create a VPC (Virtual Private Cloud)
Create VPC button to create a new VPC.Create to create the VPC.Configure VPC Subnets
Subnets section in the VPC console.Create subnet button to create a new subnet.Create Security Groups
Security Groups section in the VPC console.Create security group button to create a new security group.Launch Amazon DocumentDB Cluster in VPC
Create database to create a new DocumentDB cluster.Network & Security section, select the VPC and subnets you created earlier.Create to launch the DocumentDB cluster in the configured VPC.Test Connectivity
Monitor and Update Security Groups
DocumentDB clusters are deployed within a VPC with properly configured subnets and security groups that restrict access to authorized sources only.
The individual is required to create a subnet and configure their inbound and outbound access. Individuals are supposed to configure and route, ensuring the traffic is flowing smoothly without any interference. This control is important because it only allows authorized users to access their resources as they prefer.
Amazon DocumentDB must be deployed within a VPC. Default security groups may allow broader access than necessary.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 12.2 Establish and Maintain a Secure Network Architecture | X | X | |
| v7 | 11.7 Manage Network Infrastructure Through a Dedicated Network | X | X |
Level 1 | Manual