Security Groups Discipline

Tight scoping.

Overview

Security groups are the AWS network-control surface most teams over-permission. Loose rules accumulate until the cluster has 0.0.0.0/0 ingress on ports nobody can defend. The discipline below keeps the rules tight and version-controlled.

The approach

Four habits keep security groups tight: prefer SG-to-SG references, name every rule, manage in IaC, and review quarterly.

Why this compounds

Each tightened rule reduces attack surface for the lifetime of the rule. Compounded across hundreds of rules per account, the posture improves measurably.