| name | cis-aws-euc-4.8 |
| description | Ensure any user that has not accessed WorkDocs in 30 days is set to inactive |
| category | cis-end-user-compute |
| version | 1.2.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","end-user-compute","workdocs","user-management","account-lifecycle"] |
| cis_id | 4.8 |
| cis_benchmark | CIS AWS End User Compute Services Benchmark v1.2.0 |
| tech_stack | ["aws"] |
| cwe_ids | ["CWE-263"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Ensure any user that has not accessed WorkDocs in 30 days is set to inactive (Manual)
Profile Applicability
Description
User accounts that are not actively using the WorkDocs service should be set to inactive after a period of 30 days.
Rationale
Inactive accounts may appear to not pose a problem but they can provide unauthorized access to files within WorkDocs.
Impact
Changing a user to Inactive status does not delete their files, folders, or feedback from your Amazon WorkDocs site.
Audit Procedure
Perform the following steps to review list of users.
Using WorkDocs Admin Control Panel
- Log in to WorkDocs as an Administrator
- Under My Account, choose Open admin control panel
- Under Manage Users, choose Download user
- For Download user, choose All users
- Review the file to determine if any users have not accessed WorkDocs in the past 30 days
If you find any users that have not accessed WorkDocs in the past 30 days refer to the remediation below.
Using AWS Console
Not applicable - must be audited via WorkDocs Admin control panel.
Expected Result
All users who have not accessed WorkDocs in 30+ days are set to inactive status.
Remediation
Using WorkDocs Admin Control Panel
Perform the steps below to disable a user's access by changing their status to Inactive:
- Log in to WorkDocs as an Administrator
- Under My Account, click Open admin control panel
- Under Manage Users, choose the pencil icon next to the user's name that needs to be set as inactive
- Choose Inactive, and Click Save Changes
The inactivated user no longer has access to your Amazon WorkDocs site.
Using AWS CLI
Not applicable - must be configured via WorkDocs Admin control panel.
Default Value
By default, there is no setting to manage inactive users.
References
- https://docs.aws.amazon.com/workdocs/latest/adminguide/inactive-user.html
CIS Controls
v8: