Skip to main content

💼 2.13 Ensure IAM users receive permissions only through groups (Automated)

  • ID: /frameworks/cis-aws-v7.0.0/02/13

Description

IAM users are granted access to services, functions, and data through IAM policies. There are four ways to assign policies to a user:

  1. Attach an inline (user) policy directly to the user
  2. Attach a managed policy directly to the user
  3. Add the user to an IAM group with attached policies
  4. Add the user to an IAM group with inline policies

Only assigning permissions through IAM groups is recommended.

Similar

  • Sections
    • /frameworks/cis-aws-v6.0.0/02/14

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS AWS v6.0.0 → 💼 2.14 Ensure IAM users receive permissions only through groups (Automated)1no data

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
💼 CIS AWS v6.0.0 → 💼 2.14 Ensure IAM users receive permissions only through groups (Automated)1no data

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (1)

PolicyLogic CountFlagsCompliance
🛡️ AWS IAM User has inline or directly attached policies🟢1🟠 x1, 🟢 x5no data