πΌ 1.5 Ensure MFA is enabled for the 'root' user account
- Contextual name: πΌ 1.5 Ensure MFA is enabled for the 'root' user account
- ID:
/frameworks/cis-aws-v1.4.0/01/05
- Located in: πΌ 1 Identity and Access Management
Descriptionβ
The 'root' user account is the most privileged user in an AWS account. Multi-factor Authentication (MFA) adds an extra layer of protection on top of a username and password. With MFA enabled, when a user signs in to an AWS website, they will be prompted for their username and password as well as for an authentication code from their AWS MFA device.
Note: When virtual MFA is used for 'root' accounts, it is recommended that the device used is NOT a personal device, but rather a dedicated mobile device (tablet or phone) that is managed to be kept charged and secured independent of any individual personal devices. ("non-personal virtual MFA") This lessens the risks of losing access to the MFA due to device loss, device trade-in or if the individual owning the device is no longer employed at the company.
Similarβ
- Sections
/frameworks/cis-aws-v1.5.0/01/05
/frameworks/cis-aws-v1.3.0/01/05
- Internal
Similar Sections (Take Policies From)β
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (1)β