Skip to main content

IAM Policy Allows Access To CloudTrail Privileges

Overview

Check that no IAM policies granting unrestricted CloudTrail privileges are generated. As CloudTrail holds significant importance, it's imperative for IAM policies to adhere to the principle of least privilege, especially for this service. Opting for a minimal permission set initially, and then adding permissions as needed, is a more secure approach. It's recommended to begin with conservative permissions and then progressively enhance them, rather than starting with excessively permissive access and attempting to restrict later. Enumerate the policies and assess whether the permissions granted are truly essential for conducting business tasks at hand.

Vendor

AWS

Cloud Service

IAM

References

http://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html, https://docs.aws.amazon.com/IAM/latest/APIReference/API_ListPolicies.html, https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html

Severity

3

Item Types

AWS::IAM::ManagedPolicy