AWS New Checks

Ensure no Customer Managed IAM policies allow actions that may lead into Privilege Escalation
Profile Applicability: Level 1 Description: This control ensures that customer-managed IAM policies do not include permissions that can lead to privilege...
Tue, 14 Oct, 2025 at 2:47 AM
Ensure that the IAM password policy prohibits password reuse, specifically 24 or greater.
Profile Applicability: Level 1 Description: This control ensures that the AWS Identity and Access Management (IAM) password policy prevents users from re...
Tue, 14 Oct, 2025 at 2:44 AM
Ensure that IAM policies are attached only to groups or roles.
Profile Applicability: Level 1 Description: This control ensures that AWS Identity and Access Management (IAM) policies are attached only to groups or ro...
Tue, 14 Oct, 2025 at 2:38 AM
Ensure that IAM password policy requires at least one lowercase letter.
Profile Applicability: Level 1 Description: This control ensures that the AWS Identity and Access Management (IAM) password policy requires all user pass...
Tue, 14 Oct, 2025 at 2:33 AM
Ensure IAM password policy requires at least one uppercase letter
Profile Applicability: Level 1 Description: This control ensures that the AWS Identity and Access Management (IAM) password policy requires all user pass...
Tue, 14 Oct, 2025 at 2:26 AM
Ensure MFA is enabled for the root account.
Profile Applicability: Level 1 Description: This control ensures that Multi-Factor Authentication (MFA) is enabled for the AWS root account. The root acc...
Tue, 14 Oct, 2025 at 2:22 AM
Ensure that access keys are not set up during initial user setup for all IAM users that have a console password.
Profile Applicability: Level 1 Description: This control ensures that IAM users who have console access (a username and password) are not provisioned wit...
Tue, 14 Oct, 2025 at 2:18 AM
Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed.
Profile Applicability: Level 1 Description: This control ensures that all expired SSL/TLS certificates stored in AWS Identity and Access Management (IAM)...
Tue, 14 Oct, 2025 at 2:12 AM
Ensure IAM password policy expires passwords within 90 days or less.
Profile Applicability: Level 1 Description: This control ensures that the AWS Identity and Access Management (IAM) password policy enforces password expi...
Tue, 14 Oct, 2025 at 2:08 AM
Ensure that users within groups holding AdministratorAccess policy have multi-factor authentication (MFA) tokens activated.
Profile Applicability: Level 1 Description: This control ensures that all IAM users who are members of groups granted the AdministratorAccess managed pol...
Tue, 14 Oct, 2025 at 2:02 AM