Skip to content
This repository has been archived by the owner on Jul 22, 2021. It is now read-only.

Should the AdministratorAccess Managed Policy count? #89

Open
bwhaley opened this issue Jul 30, 2019 · 0 comments
Open

Should the AdministratorAccess Managed Policy count? #89

bwhaley opened this issue Jul 30, 2019 · 0 comments

Comments

@bwhaley
Copy link

bwhaley commented Jul 30, 2019

I notice that check 1.24 searches only locally scoped policies. I agree that this seems to satisfy the intent of the requirement, which states:

Ensure IAM policies that allow full ":" administrative privileges are not created

(emphasis on the not created).

However, the audit step doesn't say anything about local scope, and if one didn't include local scope, this requirement would not be achievable as the admin managed policy cannot be deleted. At at minimum, it does seem like the admin policy shouldn't be attached for the requirement to be satisfied. This is currently skipped in the audit.

What are your thoughts?

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant