IAM: GetAccountSummary - 'Root Account MFA enabled'

Information

AWS Multi-factor authentication (MFA) provides an extra level of security for sign-in credentials. With MFA enabled, when users signs in to an AWS website, they will be prompted for their user name and password (the first factor - what they know), as well as for an authentication code from their MFA device (the second factor - what they have).

Solution

An MFA device should be assigned to the root account of the IAM entity.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CCE|CCE-78901-6, CSCv6|5.6, CSCv6|12.6, CSCv6|16.11

Plugin: amazon_aws

Control ID: 192c0623dc0208867aff692252fa90d67b640e1279fab628036d288090a8733d