IAM: GetGroup - 'Group membership should be reviewed'

Information

Proper group membership helps ensure that data remains confidential and secure.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Members of each group should be reviewed. If any group memebers are not documented they should be investigated and/or removed.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-1, 800-53|AC-2, 800-53|AC-5, 800-53|AC-6, 800-53|AU-1, 800-53|AU-6, 800-53|IA-1, 800-53|SI-1, 800-53|SI-4

Plugin: amazon_aws

Control ID: d6b76f9c60335a5051f4ce48c5ba374b5c0bf1f9ff0b4f006ed5390f44b6021b