설명
AWS 루트 사용자는 계정에 광범위한 권한을 가집니다. 일상 작업에는 사용을 피하고, 사용한 경우에는 담당자가 확인할 수 있도록 모니터링하세요.
잠재적 영향
알림이 없으면 승인되지 않은 루트 사용자 활동을 발견하고 대응하는 데 시간이 더 걸릴 수 있습니다.
해결 방법
루트 사용자 활동을 수집하는 로그 메트릭 필터와 해당 지표의 알람을 구성하세요. 사용 여부를 확인할 담당자에게 알림이 전달되도록 설정하세요.
예시
예시는 AWS 서비스가 대신 수행한 이벤트를 제외하는 필터와 알람의 지표 연결을 보여 줍니다. CloudTrail 로그 전달과 알림 대상은 별도로 구성하세요.
변경 전
hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-RootAccountUsage"
pattern = "{ $.userIdentity.type = \"Root\" && $.userIdentity.invokedBy NOT EXISTS && $.eventType != \"AwsServiceEvent\" }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-RootAccountUsage"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.3-RootAccountUsage"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = "XXX NOT YOUR FILTER XXX"
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}
변경 후
hcl
resource "aws_cloudwatch_log_metric_filter" "example" {
name = "CIS-RootAccountUsage"
pattern = "{ $.userIdentity.type = \"Root\" && $.userIdentity.invokedBy NOT EXISTS && $.eventType != \"AwsServiceEvent\" }"
log_group_name = aws_cloudwatch_log_group.CIS_CloudWatch_LogsGroup.name
metric_transformation {
name = "CIS-RootAccountUsage"
namespace = "CIS_Metric_Alarm_Namespace"
value = "1"
}
}
resource "aws_cloudwatch_metric_alarm" "example" {
alarm_name = "CIS-3.3-RootAccountUsage"
comparison_operator = "GreaterThanOrEqualToThreshold"
evaluation_periods = "1"
metric_name = aws_cloudwatch_log_metric_filter.example.id
namespace = "CIS_Metric_Alarm_Namespace"
period = "300"
statistic = "Sum"
threshold = "1"
}