Security Group Best Practices

Tight scoping.

Overview

AWS Security Groups are the stateful firewall layer attached to every ENI; they decide which traffic reaches the workload. The difference between a tight SG posture and a sloppy one is the difference between a contained compromise and a network-wide one. Hygiene matters more than any single rule because it catches whole classes of exposure that single-rule audits miss.

The approach

Three habits keep SG sprawl under control: SG-to-SG references for east-west traffic, named rules with descriptions, and IaC management with periodic review.

Why this compounds

Each tightened rule and each refactored CIDR-to-SG reference reduces attack surface a little more. The team's network mental model sharpens; new services inherit the conventions instead of recreating sprawl.