Skip to main content

Unused Amazon EC2 security groups should be removed

Severity: Medium

Resource Types: AWS::EC2::SecurityGroup

Description

This AWS control checks that security groups are attached to Amazon Elastic Compute Cloud (Amazon EC2) instances or to an elastic network interface. The control will fail if the security group is not associated with an Amazon EC2 instance or an elastic network interface.

Remediation

To create, assign and delete security groups, see Security groups in Amazon EC2 user guide.