Medium
IAM
Password policies for IAM users should have strong configurations
NIST 800-53NIST 800-171ISO 27001PCI DSS v4.0.1HIPAA
Description
Checks if password policies for IAM users have strong AWS configurations.
Remediation
To ensure that password policies for IAM users have strong AWS configurations, follow these steps:
Steps
- Log into the AWS Management Console with an account that has administrative privileges.
- Navigate to the IAM dashboard.
- Select 'Account settings' from the navigation pane to access the password policy settings.
- Review and update the password policy to ensure it includes the following strong configurations:
- - Require at least one uppercase letter.
- - Require at least one lowercase letter.
- - Require at least one number.
- - Require at least one non-alphanumeric character.
- - Set a minimum password length of 8 characters.
- - Enable password expiration and set the maximum password age to 90 days or less.
- - Prevent password reuse by setting the number of remembered passwords to 24 or more.
- Save the updated password policy.
- Communicate the new password requirements to all IAM users and ensure they update their passwords accordingly.
Compliance
NIST 800-53NIST 800-171ISO 27001PCI DSS v4.0.1HIPAA