AWS Password Policy Enforces Password Age Limit Of 90 Days Or Less
This policy validates that the account password policy enforces a maximum password age of 90 days or less.
Enforcing a max password age means that passwords will be regularly rotated. This is considered best security practice as it reduces the time possible for attackers to compromise passwords, and to make use of compromised credentials.
Remediation
To remediate this, set the account password policy's max password age to 90 days or less.
References
CIS AWS Benchmark 1.11 "Ensure IAM password policy expires passwords within 90 days or less".
Last updated