Control: AWS > PCI v3.2.1 > IAM > 1 IAM root user access key should not exist
This control checks whether user access keys exist for the root user.
Remediation
To delete access keys
- Log in to your account using the root user credentials.
- Choose the account name near the top-right corner of the page and then choose My Security Credentials.
- In the pop-up warning, choose Continue to Security Credentials.
- Choose
Access keys (access key ID and secret access key)
. - To permanently delete the key, choose Delete and then choose Yes. You cannot recover deleted keys.
- If there is more than one root user access key, then repeat steps 4 and 5 for each key.
PCI requirement(s): 2.1, 2.2, 7.2.1
Resource Types
This control targets the following resource types:
Category
In Your Workspace
Developers
- tmod:@turbot/aws-pciv3-2-1#/control/types/iamRootUserNoAccessKeys
- tmod:@turbot/turbot#/control/categories/compliancePci
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/aws-pciv3-2-1#/control/types/iamRootUserNoAccessKeys"
Get Controls
Control Type URI
Category URI
GraphQL
CLI