EC2: DescribeKeyPairs - 'Key names currently in use'

Information

Access keys are used to digitally sign API calls made to AWS services. Each access key credential is comprised of an access key ID and a secret key. The secret key portion must be secured by the AWS account holder or the IAM user to whom they are assigned.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Review the current key names. If any are missing or undocumented they should be reviewed.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION, SYSTEM AND INFORMATION INTEGRITY

References: 800-53|AC-18, 800-53|IA-3, 800-53|IA-7, 800-53|SC-7, 800-53|SC-8, 800-53|SC-9, 800-53|SC-12, 800-53|SC-13, 800-53|SC-16, 800-53|SC-17, 800-53|SC-23, 800-53|SC-28, 800-53|SI-8

Plugin: amazon_aws

Control ID: 599d326600d1ae4f1a5a0538bd79d740eec827b067c413113688fcf7052c047e