Skip to main content

Restrict Public IP Access on MLDE Instances

CCC.MLDE.CN07 · Networking

Prevent public IP access to MLDE instances to reduce exposure to the internet and enhance security.

Related Capabilities

IDTitleDescription
CCC.MLDE.CP01Managed Notebook EnvironmentsProvides fully managed notebook instances specifically designed for machine learning development, eliminating the need to manage underlying infrastructure.
CCC.MLDE.CP07Data Pipeline IntegrationSupports integration with data preparation and feature engineering pipelines, including versioning of datasets and capabilities used in ML experiments.
CCC.MLDE.CP08Model RegistryProvides centralized storage and versioning for trained models, including metadata about training runs, model artifacts, and deployment history.
CCC.VPC.CP04Public Subnet CreationAbility to create a subnet that allows resources within the subnet to communicate with the public internet.

Related Threats

IDTitleDescription
CCC.MLDE.TH02Training Data or Model Artifacts are ExfiltratedNotebook instances and connected data pipelines may be configured with unrestricted egress paths, such as file downloads, public network interfaces, or writable external destinations. Training datasets, model artifacts, and embedded credentials could be transferred out of the environment through these paths. This results in a loss of confidentiality for proprietary data and models, and may expose regulated or sensitive records used in training.
CCC.VPC.TH02Exposure of Resources to Public InternetAssignment of external IP addresses to resources exposes resources to the public internet, increasing the risk of attacks such as brute force, exploitation of vulnerabilities, or unauthorized access.

Assessment Requirements

IDTextApplicability
CCC.MLDE.CN07.AR01Verify that MLDE instances containing sensitive data cannot be accessed via public IP addresses.tlp-red
CCC.MLDE.CN07.AR02For MLDE instances without sensitive data requiring public access, ensure that appropriate security controls are in place and access is approved.tlp-red, tlp-amber, tlp-green, tlp-clear

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.AC-3
CCMSEF-05
ISO_270012013 A.13.1.1
NIST_800_53SC-7