High
IAM
Regional
IAM Access Analyzer external access analyzer should be enabled
CIS v5.0.0
Description
Confirms that the AWS account has an IAM Access Analyzer external access analyzer enabled in the current region.
Remediation
To remediate missing IAM Access Analyzer external access analyzer, you need to create and enable an external access analyzer in each AWS Region.
Steps
- Navigate to the AWS IAM Access Analyzer console
- Select the AWS Region where you want to enable the analyzer
- Click 'Create analyzer'
- Select 'External access analyzer' as the analyzer type
- Choose the scope (organization or individual account)
- Configure the analyzer settings
- Review and create the analyzer
- Verify the analyzer is active and running
- Repeat for all required AWS Regions
- Set up monitoring and alerting for analyzer findings
Compliance
CIS v5.0.0