Low
IAM
Ensure IAM password policy expires passwords within 90 days or less
CISISO 27001HIPAA
Description
This check ensures that the IAM password policy is configured to expire passwords within 90 days or less.
Remediation
To configure the IAM password policy to expire passwords within 90 days or less, follow these steps:
Steps
- Sign in to the AWS Management Console with an account that has IAM permissions.
- Open the IAM console at https://console.aws.amazon.com/iam/.
- In the navigation pane, click on 'Account settings'.
- Scroll down to the 'Password policy' section.
- Click on 'Edit password policy'.
- Under 'Password expiration', check the box for 'Enable password expiration'.
- Set 'Password expiration period' to 90 days or less.
- Click on 'Save changes' to apply the new password policy.
Compliance
CISISO 27001HIPAA