Low
IAM
IAM users should not have IAM policies attached
PCI DSSCISNISTISO 27001HIPAA
Description
Flags IAM users with policies attached directly rather than through groups or roles.
Remediation
To ensure IAM users do not have IAM policies attached, follow these steps:
Steps
- Log into the AWS Management Console with an account that has administrative privileges.
- Navigate to the IAM dashboard and select 'Users' from the navigation pane.
- Review each IAM user to identify if any IAM policies are directly attached.
- For users with directly attached policies, click on the user name to view their permissions.
- In the 'Permissions' tab, identify and detach any directly attached policies.
- Use IAM groups or roles to assign permissions instead of attaching directly to users.
- Add the IAM users to the appropriate groups or assign them the appropriate roles.
Compliance
PCI DSSCISNISTISO 27001HIPAA