IAM: GetAccountSummary - 'GroupsQuota <= 100'

Information

This value controls the maximum number of groups allowed for the AWS account.

Solution

Set the maximum number of groups allowed for the AWS account to an appropriate value. By default this value is set to 300. This value can be changed using the AWS Service Quotas Dashboard in the Management Console.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, AUDIT AND ACCOUNTABILITY, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-1, 800-53|AC-2, 800-53|AC-5, 800-53|AC-6, 800-53|AU-1, 800-53|AU-6, 800-53|IA-1, 800-53|SI-1, 800-53|SI-4

Plugin: amazon_aws

Control ID: 31de749b500abc40ac3ab2578017644da7eba925e01a4c570218c0e6e412329e