Skip to main content

πŸ’Ό IA-2(8) Identification and Authentication (organizational Users) | Access to Accounts β€” Replay Resistant

Description​

Implement replay-resistant authentication mechanisms for access to [Selection (one or more): privileged accounts; non-privileged accounts].

Similar​

  • Sections
    • /frameworks/aws-fsbp-v1.0.0/iam/05
    • /frameworks/aws-fsbp-v1.0.0/iam/06
  • Internal
    • ID: dec-c-fb2286b2

Similar Sections (Take Policies From)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [IAM.5] MFA should be enabled for all IAM users that have a console password1
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [IAM.6] Hardware MFA should be enabled for the root user1

Similar Sections (Give Policies To)​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό IA-2(8) Access to Accounts β€” Replay Resistant (L)(M)(H)2
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό IA-2(8) Access to Accounts β€” Replay Resistant (L)(M)(H)2

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlags

Policies (2)​

PolicyLogic CountFlags
πŸ“ AWS Account Root User Hardware MFA is not enabled. 🟒🟒 x3
πŸ“ AWS IAM User MFA is not enabled for all users with console password 🟒1🟒 x6