Skip to main content

💼 IA-2(8) Identification and Authentication (organizational Users) | Access to Accounts — Replay Resistant

Description

Implement replay-resistant authentication mechanisms for access to [Selection (one or more): privileged accounts; non-privileged accounts].

Similar

  • Sections
    • /frameworks/aws-fsbp-v1.0.0/iam/05
    • /frameworks/aws-fsbp-v1.0.0/iam/06
  • Internal
    • ID: dec-c-fb2286b2

Similar Sections (Take Policies From)

SectionSub SectionsInternal RulesPoliciesFlags
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [IAM.5] MFA should be enabled for all IAM users that have a console password1
💼 AWS Foundational Security Best Practices v1.0.0 → 💼 [IAM.6] Hardware MFA should be enabled for the root user1

Similar Sections (Give Policies To)

SectionSub SectionsInternal RulesPoliciesFlags
💼 FedRAMP High Security Controls → 💼 IA-2(8) Access to Accounts — Replay Resistant (L)(M)(H)2
💼 FedRAMP Low Security Controls → 💼 IA-2(8) Access to Accounts — Replay Resistant (L)(M)(H)2

Sub Sections

SectionSub SectionsInternal RulesPoliciesFlags

Policies (2)

PolicyLogic CountFlags
📝 AWS Account Root User Hardware MFA is not enabled. 🟢🟢 x3
📝 AWS IAM User MFA is not enabled for all users with console password 🟢1🟢 x6