Earlier quoted context omitted.
Can you share what the high-level goal of the project was? i.e. was the VP trying to reduce risk? scale out responsibility for managing access?
I'm dealing with the same type of nonsense currently, as an internal audit team sees security groups being flagged by the scanning software that are open to 0.0.0.0/0 which is automatically "bad", even though the hosts have no public IP's and are being automatically managed by EKS to setup links to k8s NodePorts and the ELB. Same with security groups. Gartner has some "best practice" doc somewhere, someone loads that…
I'm not up on EKS-ELB these days, but if the nodes only allow ingress to NodePorts from the ELB, then it seems like those findings should be suppressed in most orgs.
If the SecEng team was partnering with the delivery team they'd know that before sending the report.