Turbot Guardrails Hub 
Hub
  • Mods
  • Policy Packs
  • Docs
  • Home
ModsPolicy PacksDocsHome
Mods
AWS
Loading resources...

Resource Type: AWS > IAM > Group

The IAM Group resource type is part of the AWS Identity and Access Management (IAM) service. Each IAM Group resource is a collection of IAM users and is used to manage permissions for multiple users.

Resource Context

Group is a part of the IAM service.

Each Group lives under an Account.

Each Group may have children of these types:
  • Group Policy Attachments
  • Inline Policy

Controls

The primary controls for AWS > IAM > Group are:

  • Active
  • Approved
  • CMDB
  • Configured
  • Discovery
  • Intelligent Assessment
  • Policy Attachments
  • ServiceNow
  • Usage

It is also targeted by these controls:

  • AWS > HIPAA > IAM > IAM groups should have at least one user
  • AWS > HIPAA > IAM > KMS key decryption should be restricted in IAM inline policy
  • AWS > IAM > Group > Group Policy Attachments > Discovery
  • AWS > IAM > Group > Inline Policy > Discovery
  • AWS > NIST 800-53 > IAM > IAM groups should have at least one user
  • AWS > NIST 800-53 > IAM > IAM groups, users, and roles should not have any inline policies
  • AWS > Turbot > IAM > Group > Managed

Quick Actions

  • Attach Group Policies
  • Delete
  • Delete from AWS
  • Detach and delete
  • Detach Policies
  • IAM Group Managed
  • Router
  • Skip alarm for Active control
  • Skip alarm for Active control [90 days]
  • Skip alarm for Approved control
  • Skip alarm for Approved control [90 days]

Category

  • IAM

In Your Workspace

  • Controls by Resource Type report
  • Policy Settings by Resource Type report
  • Resources by Resource Type report

Developers

    Resource Type URI
    • tmod:@turbot/aws-iam#/resource/types/group
  • Category URI
    • tmod:@turbot/turbot#/resource/categories/iam
  • GraphQL
    • query resource(id: "tmod:@turbot/aws-iam#/resource/types/group") { … }
    • query resourceActivities(filter: "resourceId:'tmod:@turbot/aws-iam#/resource/types/group'") { … }
    • mutation createResource(input: { … })
    • mutation updateResource(input: { … })
  • CLI
    • Get Resource
    • turbot graphql resource --id "tmod:@turbot/aws-iam#/resource/types/group"
  • Steampipe Query
    • Get Resource
    • select * from guardrails_resource where resource_type_uri = 'tmod:@turbot/aws-iam#/resource/types/group';
    • Get Policy Settings (By Resource ID)
    • select * from guardrails_policy_setting where filter = 'resourceTypeId:"tmod:@turbot/aws-iam#/resource/types/group"';
    • Get Resource Notification
    • select * from guardrails_notification where resource_type_uri = 'tmod:@turbot/aws-iam#/resource/types/group' and notification_type in ('resource_updated', 'resource_created');
Guardrails
Guardrails Hub
  • Hub
  • Docs
  • Blog
  • Changelog
Products
  • GuardrailsGuardrails
  • PipesPipes
  • SteampipeSteampipe
  • PowerpipePowerpipe
  • FlowpipeFlowpipe
  • TailpipeTailpipe
Turbot
  • Home
  • About us
  • We're hiring!
  • Contact us
Community

Our community of practitioners love to discuss cloud governance & security.

Slack logoJoin us on Slack →

System StatusLegalSecurity
Terms of UseSecurityPrivacy
180
Mods
497
Resource Types
8,691
Policies
3,362
Controls
1,833
Quick Actions
540
IAM