a year ago
CIS Benchmark version 1.4.0 Rule Bundle update for unused credentials
Stax has released an update to the CIS Benchmark version 1.4.0 bundle to align with a change introduced to rule 1.12 in the CIS 1.4 Amazon Web Services Foundation Benchmark specification.
The following rule has been removed from the CIS Benchmark version 1.4.0 Rule Bundle:
- CIS 1.12 - Ensure access keys are rotated every 90 days or less
The following rule has been added to the CIS Benchmark version 1.4.0 Rule Bundle:
- CIS 1.12 - Ensure credentials unused for 45 days or greater are disabled
To avoid any loss of historical compliance data, Stax has automatically added the removed rule to your Organization Rules Bundle for customers that had CIS1.4 enabled. If you do not wish to keep the rule, you can remove it from your Organization Rules Bundle by following the process to Disable a Rule.