Skip to main content

CCC.IAM.C01: Restrict IAM User Credentials Creation

Control ID:CCC.IAM.C01
Title:Restrict IAM User Credentials Creation
Objective:Prevent non-administrative principals from creating new long-lived credentials like access keys or generating temporary session tokens. This blocks a common privilege escalation and persistence vector.
Control Family:
Identity and Access Management

Related Threats

IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.IAM.TH03Overly-Permissive Identity Trust PolicyAn IAM role or service principal's trust policy is configured to allow principals from untrusted or overly broad scopes, such as any identity in any account, to assume or impersonate it. This can allow an external or unauthorized identity to gain access to the cloud environment, completely bypassing internal identity controls.
1
1
0

Related Capabilities

IDTitleDescription
CCC.IAM.F06IAM Roles / Service PrincipalsAbility to create, manage, list and delete IAM roles. IAM role is an identity for applications or services to access resources.
CCC.IAM.F12Policy ConditionsAbility to use conditions to add additional restrictions to the permission being granted. Allow access control rules to apply only when certain conditions are met.
CCC.IAM.F15Role Assumption / DelegationAbility to temporarily assume another role or delegate access. Commonly used for user impersonation or temporary privilege elevation.

Guideline Mappings

Reference IDEntry IDStrengthRemarks
NIST-CSF
PR.AA-05
0
-
NIST_800_53
AC-2
0
-
NIST_800_53
AC-3
0
-
NIST_800_53
AC-5
0
-
NIST_800_53
AC-6
0
-

Assessment Requirements

IDDescriptionApplicability
CCC.IAM.C01.TR01When an identity policy for a non-administrative principal is evaluated, it MUST NOT grant permissions for creating credentials or generating temporary session tokens.
tlp-clear
tlp-green
tlp-amber
tlp-red
CCC.IAM.C01.TR02When a non-administrative principal attempts to create new credentials or a temporary session token, the service MUST deny the action.
tlp-clear
tlp-green
tlp-amber
tlp-red