Security and compliance best practices

更新时间:
复制 MD 格式

Harden your ECS workloads across five realms: OS security, data security, identity and access control, network security, and security audit.

Overview

  • Basic security solutions: Recommended for all scenarios. Cover the basic requirements for securing cloud assets.

  • Enhanced security solutions: Recommended for security-sensitive or compliance-critical enterprise workloads.

Security type

Security child class

Best practices

Basic security solution

Enhanced security solution

Operating system security

Credential security

Avoid using weak security tokens to log on to instances

Recommended

Recommended

Network-based access control

Restrict access to O&M ports of instances by source IP address

Recommended

Recommended

Vulnerability management

Enable host protection

Recommended

Recommended

Vulnerability management

Fix important security vulnerabilities

Recommended

Recommended

Privileged access management

Avoid using the root account to log on to instances

Recommended

Credential security

Avoid preset image credentials

Recommended

Supply chain security

Restrict the images that can be used to create instances

Recommended

Monitoring and alerts

Enable abnormal logon detection

Recommended

Data security

Data protection

Enable an automatic snapshot policy for disks

Recommended

Recommended

Sensitive information

Require HTTPS for ECS OpenAPI calls

Recommended

Recommended

Supply chain security

Prevent accidental disclosure of sensitive information from images and snapshots

Recommended

Encryption

Use encrypted disks

Recommended

Encryption

Use the strengthened mode to access instance metadata

Recommended

Identity and access control

Credential security

Protect your Alibaba Cloud account to prevent credential leaks

Recommended

Recommended

Privileged access management

Avoid using your Alibaba Cloud account. Grant different permissions to RAM users based on their roles.

Recommended

Recommended

Network-based access control

Restrict the source IP addresses that can be used to call OpenAPI

Recommended

Resource-level access control

Use resource groups to manage permissions by project or department

Recommended

Resource-level access control

Enable tag-based permissions

Recommended

Compliance constraint configuration

Use RAM policies to constrain cloud operation behaviors

Recommended

Network security

Network-based access control

Reduce the Internet exposure risks of ECS instances

Recommended

Recommended

Network-based access control

Use VPCs for network isolation

Recommended

Network-based access control

Use security groups for internal access control and micro-segmentation

Recommended

Network-based access control

Use network ACLs for access control

Recommended

Network-based access control

Access the cloud over an internal network

Recommended

Network-based access control

Use PrivateLink to reduce unnecessary Internet traffic

Recommended

Traffic security

Use DDoS scrubbing to defend against attacks

Recommended

Traffic security

Use Cloud Firewall to defend against attacks

Recommended

Web traffic security

Protect applications with WAF and RASP

Recommended

Security audit and O&M

Logs

Use ActionTrail to analyze cloud operations

Recommended

Recommended

Monitoring and alerts

Maintain up-to-date security contacts to promptly receive and handle security events

Recommended

Recommended

Privileged access management

Use Bastionhost for O&M and MLPS 2.0 compliance

Recommended

Logs

Record and analyze VPC traffic logs

Recommended