Skip to main content

CCC.IAM.TH09: Long-Lived Static Credentials

Threat ID:CCC.IAM.TH09
Title:Long-Lived Static Credentials
Description:

Long-lived static credentials such as access keys for an identity are used and not rotated periodically according to security best practices, extending exposure in the event of credentials compromise.

Related Capabilities

IDTitleDescription
CCC.IAM.F02IAM UsersAbility to create, manage, list and delete IAM users. IAM user represents a single person or application.
CCC.IAM.F03Long-Term CredentialsAbility to create, manage, list and delete long-term credentials such as access keys and service account keys.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1078.004
0
Valid Accounts: Cloud Accounts
MITRE-ATT&CK
T1552
0
Unsecured Credentials

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.IAM.C06Maximum Age for Long-Term Static CredentialsEnsure that long-lived static credentials like access keys are programmatically rotated within a defined time period to limit the window of opportunity if compromised. Identity Provisioning and Lifecycle
2
2
1
CCC.IAM.C09Enforce Federated Single Sign-On (SSO) for Human UsersEnsure that all human users must authenticate through a central, federated Identity Provider (IdP) to access the cloud environment. This eliminates cloud-native user accounts with long-lived passwords, centralizes authentication controls, and simplifies lifecycle management. Identity Provisioning and Lifecycle
2
2
1