Medium
IAM
IAM users' access keys should be rotated every 90 days or less
PCI DSSCISNISTISO 27001HIPAA
Description
Verifies that IAM user access keys have been rotated within the last 90 days.
Remediation
To ensure IAM users' access keys are rotated every 90 days or less, follow these steps:
Steps
- Log into the AWS Management Console with an account that has administrative privileges.
- Navigate to the IAM dashboard and select 'Users' from the navigation pane.
- For each IAM user, click on the user name to view their security credentials.
- In the 'Access keys' section, review the 'Created' date for each access key.
- Inform the IAM user about the need to rotate their access key.
- Create a new access key for the user by clicking 'Create access key'.
- Provide the new access key to the user and ensure they update their applications.
- After confirming the new key works, deactivate and delete the old access key.
Compliance
PCI DSSCISNISTISO 27001HIPAA