Risk Level: High (act today)
Rule ID: AlibabaCloud-RAM-009
Ensure that your RAM user access keys are rotated every 90 days or less in order to decrease the likelihood of accidental exposures and protect your Alibaba Cloud resources against unauthorized access.
Rotating RAM user credentials periodically will significantly reduce the chances that a compromised set of access keys can be used without your knowledge to access certain components and resources within your Alibaba Cloud account.
Audit
To determine if your Alibaba Cloud RAM users have any outdated access keys, perform the following operations:
Remediation / Resolution
To rotate (re-create) your outdated Resource Access Management (RAM) user access keys, perform the following operations:
References
- Alibaba Cloud Documentation
- Rotate AccessKey pairs of RAM users
- Create an AccessKey pair
- Delete an AccessKey pair of a RAM user
- Disable an AccessKey pair of a RAM user
- Alibaba Cloud CLI Documentation
- ListUsers
- ListAccessKeys
- CreateAccessKey
- UpdateAccessKey
- DeleteAccessKey
Publication date Feb 23, 2024