MEDIUM
Source
CloudSploit
ID
open-dns

Open DNS

Ensure that security groups does not have TCP or UDP port 53 for DNS open to the public.

While some ports such as HTTP and HTTPS are required to be open to the public to function properly, more sensitive services such as DNS should be restricted to known IP addresses.

Restrict TCP and UDP port 53 to known IP addresses