IAM: ListUsers - 'Review current user list'

Information

Identifying and managing users is an important function in protecting your assets and information.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Users should be periodically reviewed. If any users are not documented they should be investigated and/or removed.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, MAINTENANCE, PERSONNEL SECURITY, SYSTEM AND SERVICES ACQUISITION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-1, 800-53|AC-2, 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|IA-1, 800-53|IA-2, 800-53|IA-4, 800-53|IA-5, 800-53|IA-8, 800-53|MA-5, 800-53|PS-4, 800-53|PS-5, 800-53|PS-6, 800-53|SA-7, 800-53|SI-9

Plugin: amazon_aws

Control ID: 0cc86e0e466765458c8c68661e8f3f49a1aef683f622e05853143903413a6a28