Skip to main content

πŸ’Ό Credential Lifecycle Management

  • Contextual name: πŸ’Ό Credential Lifecycle Management
  • ID: /frameworks/cloudaware/identity-and-access-governance/credential-lifecycle-management
  • Located in: πŸ’Ό Identity & Access Governance

Description​

Ensuring secure creation, rotation, and retirement of credentials.

Similar​

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (17)​

PolicyLogic CountFlags
πŸ“ AWS Account IAM Password Policy minimum password length is 14 characters or less 🟒1🟒 x6
πŸ“ AWS Account IAM Password Policy Number of passwords to remember is not set to 24 🟒1🟒 x6
πŸ“ AWS Account Root User credentials were used is the last 30 days πŸ”΄πŸŸ’1πŸ”΄ x1, 🟒 x6
πŸ“ AWS Account Root User has active access keys 🟒1🟒 x6
πŸ“ AWS IAM User Access Keys are not rotated every 90 days or less 🟒1🟒 x6
πŸ“ AWS IAM User has more than one active access key 🟒1🟒 x6
πŸ“ AWS IAM User with console and programmatic access set during the initial creation 🟒🟒 x3
πŸ“ AWS IAM User with credentials unused for 45 days or more is not disabled 🟒1🟒 x6
πŸ“ Consumer Google Accounts are used 🟒🟒 x3
πŸ“ Google IAM Service Account has User-Managed Keys 🟒1🟒 x6
πŸ“ Microsoft Entra ID Account Lockout Duration is not set 60 seconds or more 🟒🟒 x3
πŸ“ Microsoft Entra ID Account Lockout Threshold is not set to 10 or less 🟒🟒 x3
πŸ“ Microsoft Entra ID Custom Banned Password List is not enforced 🟒🟒 x3
πŸ“ Microsoft Entra ID User Notify All Admins When Other Admins Reset Their Password is set No 🟒🟒 x3
πŸ“ Microsoft Entra ID User Notify Users On Password Resets is set to No 🟒🟒 x3
πŸ“ Microsoft Entra ID User Reconfirm Authentication Information is set to 0 🟒🟒 x3
πŸ“ Microsoft Entra ID User Self-Service Password Reset does not require 2 authentication methods 🟒🟒 x3