Ensure access keys are rotated every 90 days or less (Second access key)
Access keys consist of an access key ID and secret access key, which are used to sign programmatic requests that you make to AWS. AWS users need their own access keys to make programmatic calls to AWS from the AWS Command Line Interface (AWS CLI), Tools for Windows PowerShell, the AWS SDKs, or direct HTTP calls using the APIs for individual AWS services. It is recommended that all access keys be regularly rotated. Rotating access keys will reduce the window of opportunity for an access key that is associated with a compromised or terminated account to be used. Access keys should be rotated to ensure that data cannot be accessed with an old key which might have been lost, cracked, or stolen.
Risk Level: High
Cloud Entity: IAM User
CloudGuard Rule ID: D9.AWS.IAM.07
Category: Security, Identity, & Compliance
GSL LOGIC
IamUser where secondAccessKey.isActive='true' should not have secondAccessKey.lastRotated before(-90, 'days')
REMEDIATION
From Portal
- Login to the AWS Management Console: https://console.aws.amazon.com/
- Click Services
- Click IAM
- Click on Users
- Select on the relevant user
- Click on Security Credentials
- Click 'Make inactive'
- Click 'Create access key' and save the new credentials.
- Update all applications and tools to use the new access key.
- After you verified the new Access key is updated, go to the inactive Access key and click on Delete.
From Command Line
- To inactive the old access key, run:
aws iam update-access-key --access-key-id ACCESS_KEY_ID --status Inactive --user-name USER_NAME
- To delete the old access key, run:
aws iam delete-access-key --access-key ACCESS_KEY_ID --user-name USER_NAME
References
- https://d0.awsstatic.com/whitepapers/compliance/AWS_CIS_Foundations_Benchmark.pdf
- https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html#Using_CreateAccessKey_CLIAPI
- http://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html
IAM User
An IAM user is an entity that you create in AWS to represent the person or service that uses it to interact with AWS. A user in AWS consists of a name and credentials.
Compliance Frameworks
- AWS CIS Foundations v. 1.1.0
- AWS CIS Foundations v. 1.2.0
- AWS CIS Foundations v. 1.3.0
- AWS CIS Foundations v. 1.4.0
- AWS CIS Foundations v. 1.5.0
- AWS CSA CCM v.3.0.1
- AWS CloudGuard Best Practices
- AWS CloudGuard SOC2 based on AICPA TSC 2017
- AWS CloudGuard Well Architected Framework
- AWS GDPR Readiness
- AWS HIPAA
- AWS HITRUST
- AWS HITRUST v11.0.0
- AWS ISO 27001:2013
- AWS ITSG-33
- AWS LGPD regulation
- AWS MAS TRM Framework
- AWS MITRE ATT&CK Framework v10
- AWS MITRE ATT&CK Framework v11.3
- AWS NIST 800-171
- AWS NIST 800-53 Rev 4
- AWS NIST 800-53 Rev 5
- AWS NIST CSF v1.1
- AWS PCI-DSS 3.2
- AWS PCI-DSS 4.0
- AWS Security Risk Management
Updated over 1 year ago