Security Group CIDR contains large IP range
- Severity
- Info
- Service
- Security groups
- Check ID
- SG_LARGE_CIDR
What this check finds
The CIDR in a Security Group in the account contains a large IP range, defeating the purpose of restricting access with a Security Group.
Passing looks like: Security groups avoid large CIDR ranges.
How to fix it
Replace the large CIDR (e.g. 0.0.0.0/0) with a narrower IP range specific to your trusted sources. If this is for public-facing web traffic on 80/443, it may be acceptable. For management ports (22, 3389), restrict to known office IP ranges or use a VPN/bastion.
AWS console
EC2 → Security Groups → Edit inbound rules.
Compliance controls it is evidence for
A failing result counts against these controls in KloudLytics; a passing one is evidence towards them. How compliance mapping works
| Framework | Controls |
|---|---|
| PCI-DSS v4.0.1 |
|
| SOC 2 — Trust Services Criteria |
|
| NIST SP 800-53 Rev5 (Moderate) |
|
| NIST Cybersecurity Framework 2.0 |
|
| ISO/IEC 27001:2022 Annex A |
|
Checked on every scan
KloudLytics runs this check each time it scans a connected AWS account, through a read-only role, and lists every affected resource with its region. On Pro and Business a fix is written for the specific resource rather than the general case above. The exact access it needs