aquasecurity / aquasecurity/cloudsploit

AWS – "IAM Master and IAM Manager Roles" Is Obsolete

Open
#582 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
3.8k
Forks
751
Avg merge
11d 9h
Merged PRs (30d)
3

Description

The idea of having "Master" and "Manager" roles for IAM is unjustified in the scan. The documentation link links to the AWS documentation on roles themselves, which is no help. Through researching, I found that this scheme appears to come from the "CIS Amazon Web Services Foundations Benchmark", via section 1.18: "Ensure IAM Master and IAM Manager roles are active".

This section was removed in 2018. From the changelog:

>DELETE - 1.18 - Ensure IAM Master and IAM Manager roles are active- ticket 6371

This has been deleted since version 1.2.0 of the benchmark, published 05-23-2018. There doesn't appear to be a reason to keep the scan around, as it appears no longer to be a best current practice. It was only added on 2021-01-21, _long_ after the section of the benchmark was deleted.

Contributor guide

Open the contributing guide

Research direction

Start by locating the AWS scan for IAM Master and IAM Manager roles and the documentation link it uses; no file or test is named in the issue. Confirm the check corresponds to CIS AWS Foundations Benchmark section 1.18, removed in version 1.2.0, then remove the obsolete scan and verify that the deleted check is no longer reported.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, javascript
Domain
cloud, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.