Skip to main content

Identity / IAM / Controls / DEV

Restrict IAM Policies Modification

CCC.IAM.CN02 · Access

Ensure that only designated administrative accounts have the ability to create, modify, or attach policies that define permissions for other identities.

Related Capabilities

IDTitleDescription
CCC.IAM.CP02IAM UsersAbility to create, manage, list and delete IAM users. IAM user represents a single person or application.
CCC.IAM.CP06IAM Roles / Service PrincipalsAbility to create, manage, list and delete IAM roles. IAM role is an identity for applications or services to access resources.
CCC.IAM.CP10Custom RolesAbility to create, manage, list and delete custom roles. Custom roles are user-defined roles that defines what actions are allowed.

Related Threats

IDTitleDescription
CCC.IAM.TH06IAM Policies ModificationAn adversary with access to a sufficiently privileged cloud account may modify IAM policies to establish persistance or elevate their privileges.

Assessment Requirements

IDTextApplicability
CCC.IAM.CN02.AR01When an identity policy for a non-administrative principal is evaluated, it MUST NOT grant permissions for creating, updating, or attaching policies.tlp-clear, tlp-green, tlp-amber, tlp-red
CCC.IAM.CN02.AR02When a non-administrative principal attempts to create, update, or attach policies, the service MUST deny the action.tlp-clear, tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST-CSFPR.AA-05
NIST_800_53AC-2
NIST_800_53AC-3
NIST_800_53AC-5
NIST_800_53AC-6