IAM
Root account usage, MFA enforcement, password policy, IAM user privilege analysis, role trust relationships, access key rotation.
- Root account usage + MFA
- IAM password policy
- User + role privilege analysis
- Access key age + rotation
- Cross-account trust relationships
Common finding: IAM user has console access without MFA enabled — Critical, fix via SCP enforcement.