Skip to main content

💼 Credential Lifecycle Management

  • ID: /frameworks/cloudaware/identity-and-access-governance/credential-lifecycle-management

Description

Policies that enforce secure creation, rotation, and retirement of identity credentials (passwords, access keys, API keys, and service account keys).

Similar

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlagsCompliance

Policies (28)

PolicyLogic CountFlagsCompliance
🛡️ AWS Account does not have an IAM Password Policy🟢1🟢 x6no data
🛡️ AWS Account IAM Password Policy minimum password length is 14 characters or less🟢1🟢 x6no data
🛡️ AWS Account IAM Password Policy Number of passwords to remember is not set to 24🟢1🟢 x6no data
🛡️ AWS Account Root User credentials were used is the last 30 days🟢1🟢 x6no data
🛡️ AWS Account Root User has active access keys🟢1🟢 x6no data
🛡️ AWS Account Root User signing certificates are active🟢1🟢 x6no data
🛡️ AWS IAM Access Key is unused🟢1🟢 x6no data
🛡️ AWS IAM SSH Public Key are not rotated every 90 days or less🟢1🟢 x6no data
🛡️ AWS IAM User Access Keys are not rotated every 90 days or less🟢1🟢 x6no data
🛡️ AWS IAM User has more than one active access key🟢1🟢 x6no data
🛡️ AWS IAM User has more than one active SSH public key🟢1🟢 x6no data
🛡️ AWS IAM User has no active credentials🟢1🟢 x6no data
🛡️ AWS IAM User with console and programmatic access set during the initial creation🟢⚪🟢 x2, ⚪ x1no data
🛡️ AWS IAM User with credentials unused for 45 days or more is not disabled🟢1🟢 x6no data
🛡️ AWS RDS Cluster has a common master username🟢1🟢 x6no data
🛡️ AWS RDS Instance has a common master username🟢1🟢 x6no data
🛡️ Google API Key is not restricted for unspecified hosts and apps🟢⚪🟢 x2, ⚪ x1no data
🛡️ Google API Key is not restricted for unused APIs🟢1🟢 x6no data
🛡️ Google IAM Service Account has User-Managed Keys🟢1🟢 x6no data
🛡️ Google Project has API Keys🟢1🟠 x1, 🟢 x5no data
🛡️ Microsoft Entra ID Account Lockout Duration is not set 60 seconds or more🟢⚪🟢 x2, ⚪ x1no data
🛡️ Microsoft Entra ID Account Lockout Threshold is not set to 10 or less🟢⚪🟢 x2, ⚪ x1no data
🛡️ Microsoft Entra ID Custom Banned Password List is not enforced🟢⚪🟢 x2, ⚪ x1no data
🛡️ Microsoft Entra ID User Notify All Admins When Other Admins Reset Their Password is set No🟢⚪🟢 x2, ⚪ x1no data
🛡️ Microsoft Entra ID User Notify Users On Password Resets is set to No🟢⚪🟢 x2, ⚪ x1no data
🛡️ Microsoft Entra ID User Reconfirm Authentication Information is set to 0🟢⚪🟢 x2, ⚪ x1no data
🛡️ Microsoft Entra ID User Self-Service Password Reset does not require 2 authentication methods🟢⚪🟢 x2, ⚪ x1no data
🛡️ Snowflake User password is not rotated every 90 days🟢1🟢 x6no data