Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[8pt] Address AWS Security Notices (Critical and High status) #1371

Closed
RobHanna-NOAA opened this issue Dec 10, 2024 · 1 comment
Closed

[8pt] Address AWS Security Notices (Critical and High status) #1371

RobHanna-NOAA opened this issue Dec 10, 2024 · 1 comment
Assignees
Labels
AWS Fix or Contribution for running HAND FIM in AWS High Priority Sys Admin

Comments

@RobHanna-NOAA
Copy link
Contributor

RobHanna-NOAA commented Dec 10, 2024

Note: Now part of 1377 EPIC: FIM Sys Admin Tasks (and a few related FIM tasks)

This story started on Oct 24th with a meeting of various folks including Jason Whitehead, Gautam, Fernando, Matt Luck, Diwalker and a number of other folks.

The NWS 24x7 team, which is also addressing security holes based on logs in the AWS Security Hub page found a number of issues ranging from severity of Critical to Low.

By Dec 31, we need to find all for fim-dev and ras2fim that are severity of "Critical" or "High" and fix them.

A separate card, 1372, was made for medium and lower severities which should be addressed by Feb 28th, 2025 (ish).

Details on how to find the list, fix them are not in this card. This card is just a placeholder for the task.

As of Dec 10th, their appears to be 0 critical and appx 6 High severity.

We will also to keep an eye on this security page periodically moving forward. Maybe monthly at the first of the month data cleanup?

@RobHanna-NOAA RobHanna-NOAA added High Priority AWS Fix or Contribution for running HAND FIM in AWS labels Dec 10, 2024
@RobHanna-NOAA RobHanna-NOAA changed the title [13pt] Address AWS Security Notices (Critical and High status) [8pt] Address AWS Security Notices (Critical and High status) Dec 10, 2024
@RobHanna-NOAA
Copy link
Contributor Author

When I reviewed today, there were no "critical"s and six "high".

  • Two were fixed.
  • Three can not be fixed at this time. They need a note added as to why we need to keep it as is (task definitions)
  • One can not be fixed at this time as it relates to FIM-dev team members remote access to our EC2.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
AWS Fix or Contribution for running HAND FIM in AWS High Priority Sys Admin
Projects
None yet
Development

No branches or pull requests

2 participants