An API Gateway instance is considered compliant if it has IPv6 access control enabled and a valid access control list configured.
Scenarios
Use this rule to check if an API Gateway instance has IPv6 access control enabled and a valid access control list configured. This helps prevent unauthorized IP access and improve API security.
Risk level
Default risk level: Medium.
You can change the risk level as needed.
Detection logic
An API Gateway instance is considered compliant if it has IPv6 access control enabled and a valid access control list configured.
Rule details
Parameter | Description |
Rule name | Enable IPv6 access control and set a valid access control list for an API Gateway instance |
Rule identifier | |
Tag | ApiGateway |
Automatic remediation | Not supported |
Rule trigger | Periodic |
Trigger frequency | 24 hours |
Supported resource types | ACS::ApiGateway::Instance |
Input parameters | None |
Remediation
To remediate a non-compliant resource, see Use an instance-level access control policy group to control access.