Skip to main content

Identity / IAM / Capabilities / DEV

Resource-Level Access

CCC.IAM.CP11

Ability to restrict where actions are allowed, rather than the entire service. Defines the scope of the assignment.

Related Threats

IDTitleDescription
CCC.IAM.TH04Additional Cloud Credentials CreationAn adversary with access to a sufficiently privileged cloud account may create additional credentials such as access keys, service accounts and temporary credentials to establish persistance or elevate their privileges.