IAM: GetAccountPasswordPolicy - 'Number of passwords to remember >= 24'

Information

User names for AWS accounts are always email addresses. IAM user names allow for more flexibility. Your AWS account password can be anything you define. IAM user passwords can be forced to comply with a policy you define (that is, you can require minimum password length or the use of non-alphanumeric characters).

Solution

Set the Number of passwords to remember to a value greater than or equal to 24

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5, CCE|CCE-78908-1, CSCv6|5.3

Plugin: amazon_aws

Control ID: bbdf4a359c72ae63c053871a214e8852733d6e2d3ad090cde1bfbd8a29929197