Skip to main content

CCC.IAM.TH11: Unused Credentials

Threat ID:CCC.IAM.TH11
Title:Unused Credentials
Description:

Unused IAM identity that is no longer needed or monitored remains active. Its compromise is less likely to be detected, and it represents a persistent, unnecessary attack surface.

Related Capabilities

IDTitleDescription
CCC.IAM.F02IAM UsersAbility to create, manage, list and delete IAM users. IAM user represents a single person or application.
CCC.IAM.F03Long-Term CredentialsAbility to create, manage, list and delete long-term credentials such as access keys and service account keys.
CCC.IAM.F04Password ManagementAbility to create, change and delete IAM user passwords.
CCC.IAM.F06IAM Roles / Service PrincipalsAbility to create, manage, list and delete IAM roles. IAM role is an identity for applications or services to access resources.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1078.004
0
Valid Accounts: Cloud Accounts
MITRE-ATT&CK
T1552
0
Unsecured Credentials

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.IAM.C08Maximum Age for Unused CredentialsEnsure that unused IAM credentals are removed to reduce exposure in the event of potential compromise. Identity Provisioning and Lifecycle
2
2
1
CCC.IAM.C11Enable Continuous IAM Access and Usage AnalysisEnable and configure the cloud provider's native access and usage analysis services to continuously monitor for external access paths and internal unused access. Logging and Monitoring
3
5
1