IAM-03.2: MFA is enforced for human use of API/command-line interface (CLI) access. Because API/CLI access may rely on static credentials (e.g., an AWS IAM user) use of the command line or automation code could circumvent the console/portal's MFA requirement. If API/CLI session credentials are issued through the SSO portal, as long as that portal enforces MFA for authentication this requirement is typically met.
  • Control automation: Automated
  • AWS control specification: An MFA-required policy exists and is applied to at least one IAM user
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none

Description

  • Control automation: Automated
  • AWS control specification: An MFA-required policy exists and is applied to at least one IAM user
  • Azure control specification: none
  • GCP control specification: none
  • Third-party (CSPM/CNAPP) control specification: none