IAM: ListAccessKeys - 'Active Access Keys should be rotated'

Information

You can use access keys (an access key ID and secret access key) to make programmatic requests to AWS. However, we recommend that you do not use your AWS account access keys.

Additional information: http://docs.aws.amazon.com/IAM/latest/UserGuide/IAMBestPractices.html

Solution

If you do have a set of AWS access keys for your account, delete them. If you want to keep them, make sure that you rotate (change) the access keys credentials regularly.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-1, 800-53|AC-2, 800-53|AC-3, 800-53|AC-11, 800-53|AU-2, 800-53|AU-11, 800-53|IA-1, 800-53|IA-2, 800-53|IA-5, 800-53|IA-6, 800-53|IA-8, 800-53|SC-10

Plugin: amazon_aws

Control ID: b864007a5fe7867a904ad687d89c88bfe031c081aa9e9a7a143322700666720f