IAM: GetAccountPasswordPolicy - 'Password expiration is enabled'

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

User names for AWS accounts are always email addresses. IAM user names allow for more flexibility. Your AWS account password can be anything you define. IAM user passwords can be forced to comply with a policy you define (that is, you can require minimum password length or the use of non-alphanumeric characters).

Solution

Enable the expiration of passwords.

See Also

https://d1.awsstatic.com/whitepapers/Security/AWS_Security_Best_Practices.pdf

Item Details

Category: ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION

References: 800-53|AC-1, 800-53|IA-1

Plugin: amazon_aws

Control ID: 882f4eeaf6b7fd357ebfa5721b649c929b6ab2b38459f5dd63280639f9e1d24e