IAM: ListAccessKeys - 'List of Active Access Keys'

Information

You can use access keys (an access key ID and secret access key) to make programmatic requests to AWS. However, we recommend that you do not use your AWS account access keys for normal users and reserve them for programatic access.

Additional information: http://docs.aws.amazon.com/IAM/latest/UserGuide/IAMBestPractices.html

Solution

If you don't already have a set of access keys for your account, don't create them unless you absolutely need them.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-1, 800-53|AC-2, 800-53|AC-3, 800-53|AC-11, 800-53|AU-2, 800-53|AU-11, 800-53|IA-1, 800-53|IA-2, 800-53|IA-5, 800-53|IA-6, 800-53|IA-8, 800-53|SC-10

Plugin: amazon_aws

Control ID: 11c76796bdb980b95208ad985959447b1a563dd62602207e050832d865ba0613