{
    "Behavior": "PROACTIVE",
    "ComplianceFrameworkMappings": [
        {
            "ComplianceFramework": "CIS AWS Benchmark 1.4",
            "Ids": [
                "1.15"
            ]
        },
        {
            "ComplianceFramework": "NIST 800-53 Rev 5",
            "Ids": [
                "AC-2",
                "AC-2(1)",
                "AC-3",
                "AC-3(15)",
                "AC-3(7)",
                "AC-6",
                "AC-6(3)"
            ]
        },
        {
            "ComplianceFramework": "PCI DSS version 3.2.1",
            "Ids": [
                "2.2",
                "7.1.1",
                "7.1.2",
                "7.2.1",
                "7.2.2"
            ]
        }
    ],
    "ConfigRuleIdentifier": "IAM_USER_NO_POLICIES_CHECK",
    "ControlOwner": "AWS Control Tower",
    "DeploymentMechanism": "AWS CloudFormation Hook",
    "DeploymentOwner": "AWS Control Tower",
    "Description": "This control checks whether your AWS Identity and Access Management (IAM) user has inline or managed (AWS and customer) policies directly attached. Instead, IAM users should inherit permissions from IAM groups or roles.",
    "DisplayName": "Require that an AWS Identity and Access Management (IAM) user does not have an inline or managed policy attached attached",
    "DocumentationReferences": [
        {
            "DisplayName": "IAM Least Privilege Guidance",
            "Type": "AWS Documentation",
            "Url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege"
        }
    ],
    "EvaluatedResourceTypes": [
        "AWS::IAM::User",
        "AWS::IAM::Policy",
        "AWS::IAM::ManagedPolicy"
    ],
    "EvaluatedServices": [
        "AWS Identity and Access Management (IAM)"
    ],
    "Guidance": "Elective",
    "Id": "CT.IAM.PR.4",
    "ImplementationType": "CloudFormation guard rule",
    "MinimumSupportedRuntimeVersion": "2.1",
    "Objectives": [
        {
            "Id": "CO.5",
            "Name": "Enforce least privilege"
        }
    ],
    "RegionalPreference": "REGIONAL",
    "Relationships": [
        {
            "ControlId": "SH.IAM.2",
            "ControlOwner": "AWS Security Hub",
            "RelationshipType": "Can be used with (Inclusive)"
        }
    ],
    "ReleaseDate": "2022-11-28",
    "RemediationMessage": "Configure AWS IAM users to inherit permissions from IAM groups.",
    "Severity": "LOW",
    "SupportedRegions": [
        "af-south-1",
        "ap-east-1",
        "ap-northeast-1",
        "ap-northeast-2",
        "ap-northeast-3",
        "ap-south-1",
        "ap-south-2",
        "ap-southeast-1",
        "ap-southeast-2",
        "ap-southeast-3",
        "ap-southeast-4",
        "ca-central-1",
        "eu-central-1",
        "eu-central-2",
        "eu-north-1",
        "eu-south-1",
        "eu-south-2",
        "eu-west-1",
        "eu-west-2",
        "eu-west-3",
        "il-central-1",
        "me-central-1",
        "me-south-1",
        "sa-east-1",
        "us-east-1",
        "us-east-2",
        "us-west-1",
        "us-west-2"
    ],
    "TargetOuType": "CUSTOM",
    "Version": "1",
    "Visibility": "PUBLIC"
}