IAM: GetAccountPasswordPolicy - 'Password expiration is enabled'

Information

User names for AWS accounts are always email addresses. IAM user names allow for more flexibility. Your AWS account password can be anything you define. IAM user passwords can be forced to comply with a policy you define (that is, you can require minimum password length or the use of non-alphanumeric characters).

Solution

Enable the expiration of passwords.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-1, 800-53|IA-1

Plugin: amazon_aws

Control ID: 882f4eeaf6b7fd357ebfa5721b649c929b6ab2b38459f5dd63280639f9e1d24e