Skip to main content

More Info:

Password policy should be complex enough so that users can set passwords which are not easy to guess and crack.

Risk Level

Medium

Address

Security

Compliance Standards

  • APRA CPS 234 (Australia)
  • AWS Startup Security Baseline
  • AWS Well Architected Framework
  • BSI C5 (Germany)
  • Brazil LGPD
  • CCPA / CPRA (California)
  • CIS AWS
  • CIS Critical Security Controls v8
  • CMMC 2.0
  • CSA Cloud Controls Matrix v4
  • Cloudanix Best Practice
  • DPDPA
  • Digital Operational Resilience Act (EU)
  • GDPR
  • HIPAA
  • HITRUST CSF
  • ISO 27001
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • KSA PDPL
  • MAS Technology Risk Management (Singapore)
  • MITRE ATT&CK (Cloud)
  • NIST
  • NIST CSF
  • NIST SP 800-171
  • NYDFS 23 NYCRR 500
  • PCI
  • Reserve Bank of India (RBI) Cyber Security Framework
  • Reserve Bank of India (RBI) Master Direction – Information Technology Framework
  • SOC2
  • SWIFT Customer Security Controls Framework
  • Sarbanes-Oxley IT General Controls
  • UK NCSC Cyber Assessment Framework

Triage and Remediation

How to Prevent

Using Console

To prevent the misconfiguration of not having a complex password policy in AWS IAM using the AWS Management Console, follow these steps:
  1. Navigate to IAM Dashboard:
    • Sign in to the AWS Management Console.
    • In the top navigation bar, click on “Services” and then select “IAM” under the “Security, Identity, & Compliance” section.
  2. Access Account Settings:
    • In the IAM dashboard, on the left-hand side, click on “Account settings.”
  3. Set Password Policy:
    • In the “Password policy” section, click on the “Set password policy” button.
    • Configure the password policy settings to enforce complexity. Ensure you enable options such as:
      • Require at least one uppercase letter.
      • Require at least one lowercase letter.
      • Require at least one number.
      • Require at least one non-alphanumeric character (e.g., !, @, #, $).
  4. Save Changes:
    • After configuring the desired settings, click on the “Save changes” button to apply the new password policy.
By following these steps, you can ensure that a complex password policy is enforced for IAM users in your AWS account.
To prevent the misconfiguration of not having a complex password policy in AWS IAM using the AWS CLI, you can follow these steps:
  1. Set Minimum Password Length: Ensure that the password policy enforces a minimum length for passwords. This helps in making passwords harder to guess.
  2. Require at Least One Uppercase Letter: Enforce the inclusion of at least one uppercase letter in the password to increase complexity.
  3. Require at Least One Lowercase Letter: Enforce the inclusion of at least one lowercase letter in the password to ensure a mix of character cases.
  4. Require at Least One Number and One Special Character: Ensure that the password includes at least one numeric digit and one special character to further enhance security.
By executing these commands, you can enforce a complex password policy in AWS IAM, thereby preventing the misconfiguration of having weak password policies.
To prevent the misconfiguration of not having a complex password policy in IAM using Python scripts, you can follow these steps for AWS, Azure, and GCP:

AWS (Boto3)

  1. Install Boto3: Ensure you have the Boto3 library installed. You can install it using pip if you haven’t already:
  2. Create a Python Script to Set Password Policy: Use the following script to set a complex password policy in AWS IAM:

Azure (Azure SDK for Python)

  1. Install Azure Identity and Management Libraries: Ensure you have the Azure libraries installed:
  2. Create a Python Script to Set Password Policy: Use the following script to set a complex password policy in Azure AD:

GCP (Google Cloud Client Library for Python)

  1. Install Google Cloud IAM Library: Ensure you have the Google Cloud IAM library installed:
  2. Create a Python Script to Set Password Policy: Use the following script to set a complex password policy in GCP IAM:

Summary

  • AWS: Use Boto3 to set a complex password policy directly.
  • Azure: Use Azure SDK for Python, but note that password policies are typically managed via Azure AD B2C or Conditional Access Policies.
  • GCP: Use Google Cloud IAM library, but note that password policies are typically managed via G Suite Admin SDK.
These scripts provide a starting point for ensuring complex password policies are enforced in your cloud environments.

Additional Reading: