20 of 29 in All Controls
aws

Enable IAM Access Analyzer at Organization Level

IDAWS-IAM-010
Severity
high
Automation
Manual
Category
iam
Enforcementmandatory
Complexity / Impact
low(none impact)
Cloud Scopeaws:root
Environments
productionnon-productionsandbox
Target Resources
Access Analyzer
Services
access-analyzerorganizationssecurityhub
Tags
iamaccess-analyzercross-accounttrust-relationshipsvisibilitylanding-zone
Frameworks
CIS AWSNIST 800-53ISO 27001SOC 2AWS
Governance
cloud-security-team (quarterly)
Audit Dates
2026-06-06 • 2026-06-06

Specification & Description

Enable a single IAM Access Analyzer with zone of trust set to the AWS Organization from the delegated administrator account, providing continuous detection of external access across all member accounts.

Technical Specifications

IAM Access Analyzer evaluates resource-based policies - including IAM role trust policies, S3 bucket policies, KMS key policies, and SQS queue policies - and generates findings whenever a policy grants access to a principal outside the configured zone of trust. When configured at organization level, a single analyzer covers all member accounts without requiring per-account setup. Findings are surfaced in the Access Analyzer console of the delegated administrator account and are automatically ingested by Security Hub when both services are active. This control is a prerequisite for AWS-IAM-002 (cross-account role trust detection) and other controls that rely on Access Analyzer findings.

Security Rationale

A single organization-level analyzer provides complete visibility into external access across every account at no per-evaluation cost. Without it, external trust relationships and public resource policies in member accounts are invisible to the central security team. Enabling this control is a zero-disruption, low-effort prerequisite that unlocks the detective capability for multiple downstream controls.

Policy Exceptions (1)

No exceptions are permitted. A single organization-level analyzer has no operational cost and no impact on existing resources or policies. There is no valid reason to omit it from any landing zone deployment.

Operational & Implementation Notes

Only one organization-level analyzer is needed per region. Each AWS region requires its own analyzer - deploy to all regions where resources exist, or at minimum to the primary and DR regions. The delegated administrator must be registered before attempting to create an ORGANIZATION-type analyzer; creating it from a non-delegated account will fail with an error. Access Analyzer findings are regional - a role trust policy in eu-west-1 will only appear in the analyzer deployed to eu-west-1. For multi-region coverage, automate deployment across all enabled regions via a Terraform for_each over the region list.

We value your privacy

We use analytics cookies to understand how visitors interact with our site and to improve the user experience. You can choose to accept or decline these cookies.