πΌ 1.19 Ensure that IAM External Access Analyzer is enabled for all regions (Automated)
- Contextual name: πΌ 1.19 Ensure that IAM External Access Analyzer is enabled for all regions (Automated)
- ID:
/frameworks/cis-aws-v5.0.0/01/19
- Located in: πΌ 1 Identity and Access Management
Descriptionβ
Enable the IAM External Access Analyzer regarding all resources in each active AWS
region.
IAM Access Analyzer is a technology introduced at AWS reinvent 2019. After the
Analyzer is enabled in IAM, scan results are displayed on the console showing the
accessible resources. Scans show resources that other accounts and federated users
can access, such as KMS keys and IAM roles. The results allow you to determine
whether an unintended user is permitted, making it easier for administrators to monitor
least privilege access. Access Analyzer analyzes only the policies that are applied to
resources in the same AWS Region.
Similarβ
- Sections
/frameworks/cis-aws-v4.0.1/01/20
Similar Sections (Take Policies From)β
Similar Sections (Give Policies To)β
Sub Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|
Policies (1)β