top of page
< Back

AWS Foundational Security Best Practice

IAM.1

IAM policies should not allow full *" administrative privileges"

Severity

Cloud Platforms

Resources

HIGH

AWS

AWS Identity and Access Management

This AWS control checks whether the default version of AWS Identity and Access Management (IAM) policies (also known as customer managed policies) do not have administrator access with a statement that has Effect": "Allow" with "Action": "*" over "Resource": "*". It only checks for the Customer Managed Policies that you created; but not inline and AWS Managed Policies."

6pl org white ai logo.png

(C) Copyright 2023 6PILLARS CLOUD AUTOMATION PTY LTD

bottom of page