aquasecurity / aquasecurity/cloudsploit
AWS – "IAM Master and IAM Manager Roles" Is Obsolete
- Dominant language
- JavaScript
- Stars
- 3.8k
- Forks
- 751
- Avg merge
- 11d 9h
- Merged PRs (30d)
- 3
Description
The idea of having "Master" and "Manager" roles for IAM is unjustified in the scan. The documentation link links to the AWS documentation on roles themselves, which is no help. Through researching, I found that this scheme appears to come from the "CIS Amazon Web Services Foundations Benchmark", via section 1.18: "Ensure IAM Master and IAM Manager roles are active".
This section was removed in 2018. From the changelog:
>DELETE - 1.18 - Ensure IAM Master and IAM Manager roles are active- ticket 6371
This has been deleted since version 1.2.0 of the benchmark, published 05-23-2018. There doesn't appear to be a reason to keep the scan around, as it appears no longer to be a best current practice. It was only added on 2021-01-21, _long_ after the section of the benchmark was deleted.
Contributor guide
Research direction
Start by locating the AWS scan for IAM Master and IAM Manager roles and the documentation link it uses; no file or test is named in the issue. Confirm the check corresponds to CIS AWS Foundations Benchmark section 1.18, removed in version 1.2.0, then remove the obsolete scan and verify that the deleted check is no longer reported.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, javascript
- Domain
- cloud, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100