Ensure no 'root' user account access key exists
Severity: Critical
Resource Types:
Description
This control checks whether user access keys exist for the root user.
Remediation
To delete access keys
- Log in to your account using the root user credentials.
- Choose the account name near the top-right corner of the page and then choose My Security Credentials.
- In the pop-up warning, choose Continue to Security Credentials.
- Choose
Access keys (access key ID and secret access key)
. - To permanently delete the key, choose Delete and then choose Yes. You cannot recover deleted keys.
- If there is more than one root user access key, then repeat steps 4 and 5 for each key.