Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

VPC-SC scan (feature request) #256

Open
mcapts opened this issue Sep 23, 2019 · 3 comments
Open

VPC-SC scan (feature request) #256

mcapts opened this issue Sep 23, 2019 · 3 comments
Assignees

Comments

@mcapts
Copy link

mcapts commented Sep 23, 2019

This is a feature request for having a scanner that checks VPC Service Controls to ensure the configuration is correct/appropriate.

Some basic checks like:

  • only whitelisted services are included in the perimeter
  • appropriate Access Levels are included in the perimeter
  • only projects from our organization are included in the perimeter

It may make sense to have this scan work in conjunction with an Access Context Manager scan, since Access Levels and VPC-SC are tightly coupled (and their union defines the actual security controls on the organization).

@dekuhn
Copy link
Contributor

dekuhn commented Sep 23, 2019

@blueandgold @ryanismert Can you please review this feature request. I believe we need a high level 1 pager that describes the overall scanner behavior as to when to assert a match.

@dekuhn
Copy link
Contributor

dekuhn commented Sep 24, 2019

Draft 1 pager with details to scope this work: https://docs.google.com/document/d/14wYLG1IkLXUPf6t9txhdCFiVwXtDnVjN_8QOC9IPw_o/edit

@gkowalski-google gkowalski-google transferred this issue from forseti-security/forseti-security Jan 28, 2020
@gkowalski-google
Copy link
Contributor

Resolved by PR #238

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants