This rule ensures IAM policies do not contain statements granting admin access.
Rule | IAM policy should not have statements with admin access |
Framework | General Data Protection Regulation (GDPR) |
Severity | ✔ High |
IAM Policy: Restricting admin access for General Data Protection Regulation (GDPR)
Description:
This IAM policy is designed to ensure that no user or role in the AWS account has admin access permissions in relation to the General Data Protection Regulation (GDPR). The GDPR is a regulation in EU law that addresses the privacy and protection of personal data for individuals within the European Union.
Rule Explanation:
The rule mandates that no IAM policy should include statements assigning admin access permissions with respect to GDPR. Admin access implies complete control and unrestricted capabilities, which may violate the privacy and security requirements mandated by the GDPR.
Troubleshooting Steps:
If any statements granting admin access for GDPR exist within IAM policies, follow the steps below for troubleshooting and remediation.
Necessary Codes:
No specific code is required for this policy. The process involves directly modifying IAM policies through the AWS Management Console.
Remediation Guide:
To remediate this issue, follow the step-by-step guide provided below:
Please note that modifying IAM policies must be done by users or roles with the necessary permissions to access and edit IAM policies.
By implementing this policy, you ensure that no user or role has admin access to GDPR-related resources and maintain compliance with the GDPR regulations.