IAM: ListGroupPolicies - 'Review policies assigned to groups'

Information

When you create IAM policies, follow the standard security advice of granting least privilege-that is, granting only the permissions required to perform a task. Determine what users need to do and then craft policies for them that let the users perform only those tasks.

Additional information: http://docs.aws.amazon.com/IAM/latest/UserGuide/IAMBestPractices.html

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Define the relevant policies for each group, and then assign those policies to each group.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-1, 800-53|AC-2, 800-53|AC-5, 800-53|AC-6, 800-53|AU-1, 800-53|AU-6, 800-53|IA-1, 800-53|SI-1, 800-53|SI-4

Plugin: amazon_aws

Control ID: 622152f83b32b9b29c722dc8b09b6d2445c5d0cb9386b54fcaab9c2ce5724001