AWS Security Hub · EC2
EC2.60: VPC is missing an Incident Manager endpoint
Written and reviewed by Emnode · Last reviewed
What does AWS Security Hub EC2.60 check?
EC2.60 fails any in-use VPC missing an interface endpoint for the SSM Incident Manager service (com.amazonaws.<region>.ssm-incidents). It lists VPCs with running ENIs and checks for the matching endpoint in the available state.
Why does EC2.60 matter?
Incident Manager is the service that orchestrates your response runbooks and escalations: exactly the traffic you want on the AWS private backbone rather than hairpinning through NAT to the public internet during an incident. Without the endpoint you pay NAT data-processing on every call and add an internet dependency to your incident-response path, which is also an audit finding for PCI DSS and FedRAMP workloads.
How do I fix EC2.60?
- Find VPCs without the ssm-incidents endpoint via describe-vpc-endpoints filtered on the service name.
- Create the endpoint across every AZ the workload spans with --private-dns-enabled.
- Verify the reroute by resolving the service hostname inside the VPC to an RFC1918 address.
- Add the AWS Config managed rule vpc-endpoint-enabled with ssm-incidents in its serviceNames parameter to prevent new VPCs shipping without it.
Remediation script · bash
# Move the highest-impact case first: an RDS instance in a public subnet group.
aws rds create-db-subnet-group \
--db-subnet-group-name prod-db-subnets-private \
--db-subnet-group-description "Private subnets only - no IGW route" \
--subnet-ids subnet-0aa11bb22cc33dd44 subnet-0ee55ff66aa77bb88
aws rds modify-db-instance \
--db-instance-identifier prod-payments-db \
--db-subnet-group-name prod-db-subnets-private \
--apply-immediately
# Provide a private path before moving compute, so it can still reach AWS services.
# A free S3 gateway endpoint, or a narrow interface endpoint instead of a NAT gateway.
aws ec2 create-vpc-endpoint --vpc-id vpc-0a1b2c3d \
--vpc-endpoint-type Interface \
--service-name com.amazonaws.us-east-1.ssm \
--subnet-ids subnet-0aa11 subnet-0bb22 \
--security-group-ids sg-0ccfn33 --private-dns-enabled
# Force Redshift bulk traffic through the VPC (confirm an S3 gateway endpoint exists first).
aws redshift modify-cluster \
--cluster-identifier analytics-prod --enhanced-vpc-routing Full walkthrough (console steps, edge cases and verification) in the lesson Move resources into private networks (VPC isolation).
Is EC2.60 a false positive?
A VPC missing all four EC2/ECR/Incident Manager endpoints shows up as four separate findings, not one, so enabling these controls for the first time spikes the finding count even though each is a single missing endpoint.
More EC2 controls
- EC2.1 An EBS snapshot is publicly restorable by any account
- EC2.2 Default security groups still allow traffic
- EC2.3 Attached EBS volumes are not encrypted at rest
- EC2.4 Long-stopped instances are abandoned attack surface
- EC2.6 No VPC flow logs, so there is no network audit trail
- EC2.7 New EBS volumes are not encrypted by default
- EC2.8 IMDSv1 lets an SSRF steal instance credentials
- EC2.9 Instances are directly reachable on public IPv4
- EC2.10 EC2 API traffic leaves the VPC over the internet
- EC2.13 SSH (port 22) is open to the entire internet
- EC2.14 RDP (port 3389) is open to the entire internet
- EC2.15 Subnets auto-assign public IPs to new instances