2. Audit & Enforcement Security Group Policy(审计与强制执行策略)
作用:检测并拒绝过度宽松(over-permissive)的安全组规则
两种修复模式:
手动修复(Manual Remediation):仅告警,由管理员手动处理
自动修复(Auto Remediation):通过 Lambda 自动纠正不合规规则
适用场景:强制最小权限原则,防止安全组配置错误导致风险暴露
3. Cleanup Security Group Policy(清理策略)
作用:自动识别并清理未使用的冗余安全组
适用场景:减少安全组管理复杂度,避免过期规则堆积
Policy Lifecycle
Policy Created in Firewall Manager Admin Account
↓
Target Account / OU Association
↓
AWS Config Compliance Check
├── Compliant → No Action
└── Non-Compliant → Lambda Triggered
↓
Auto-Remediation (if enabled)
↓
New EC2 Instance → Auto-attach Security Group
Policy Deleted → Auto-detach Security Group from all instances