What to Provide
(1) An export of your AWS IAM Credential Report.
(2) An export of your AWS Trusted Advisor Report for your Production AWS account.
Evidence Format
AWS-generated data table or spreadsheet in a common data file type such as .xlsx or .cvs.
Additional Guidance
(1) This evidence should demonstrate:
MFA enablement on all production accounts
A list of all AWS users and their access to resources
(2) This evidence should demonstrate:
The security compliance status of all in-scope AWS production accounts
The use and configuration of AWS security groups
A description of each resource listed in the security groups identified in your report
If you do not use AWS as your CSP for in-scope production systems, note this in the Evidence Description.
If you have accounts listed in AWS shown in your reports that do not have MFA enabled, explain why in the Evidence Description.
If, due to a business need, you do not restrict access to the AWS Security Groups listed in your reports, explain why in the Evidence Description.
Related Articles
Example Evidence
Associated Unified Control ID | Associated Framework Control |
CTRL-950 | LCL-41 |