Skip to content

Conformance Pack FedRAMP High - iam-password-policy parameters incorrectly defined #434

@caleb-mabry

Description

@caleb-mabry

Problem Statement

I am working with FedRAMP High. I noticed that even after having the correct IAM Password Policy in place, AWS Config was marking my password policy as non-compliant.

Findings

The AWS Docs note that

The true and false values for the rule parameters are case-sensitive. If true is not provided in lowercase, it will be treated as false.

https://docs.aws.amazon.com/config/latest/developerguide/iam-password-policy.html

Referenced Files

https://github.com/awslabs/aws-config-rules/blob/master/aws-config-conformance-packs/Operational-Best-Practices-for-FedRAMP-HighPart1.yaml
https://github.com/awslabs/aws-config-rules/blob/master/aws-config-conformance-packs/Operational-Best-Practices-for-FedRAMP-HighPart2.yaml

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions