// Level 4 · Control detail
4.3HighCIS · AWS

Ensure VPC default security group restricts all traffic

Default SG should be a deny-all.

Get AI-powered control detail

Plain-English explanation, CLI checks, portal steps, remediation, automation snippets, and cross-framework mappings.

3/3 free lookups remaining today

Related controls in other frameworks

finding related controls…