IAM: GetAccountSummary - 'Groups'

Information

This value represents the number of groups for the AWS account.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Review the number of groups. If the number is outside the expected value the group list should be reviewed. This value can be changed using the AWS Service Quotas Dashboard in the Management Console.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-1, 800-53|AC-2, 800-53|AC-5, 800-53|AC-6, 800-53|AU-1, 800-53|AU-6, 800-53|IA-1, 800-53|SI-1, 800-53|SI-4

Plugin: amazon_aws

Control ID: cca22dff86749925cf4327a893d5bbb4ce96393764a163dae5aebe18570f4b6c