A company security engineer must create an incident response plan for compromised IAM user account credentials. The company uses an organization in AWS Organizations and AWS IAM Identity Center to manage user access. A delegated administrator account is used to implement AWS Security Hub. That delegated administrator account has an organizational AWS CloudTrail trail that logs every event to an Amazon S3 bucket. The company has also configured an organizational event data store that captures all events from the trail.
The incident response plan must include steps the security engineer can take to immediately disable any compromised IAM user upon receiving a security-incident notification.
The plan must prevent use of the IAM user in every AWS account. It also must collect all AWS actions the compromised IAM user performed across all accounts during the preceding 7 days.
Which solution meets these requirements?
Community Discussion
No comments yet. Be the first to start the discussion!
Community Discussion