

本文属于机器翻译版本。若本译文内容与英语原文存在差异，则一律以英文原文为准。

# 限制管理权限
<a name="restrict-administrative-privileges"></a>


****  


- **对系统和应用程序的特权访问请求会在首次请求时进行验证。**
  - **实施指导:** [主题 4：管理身份](theme-4.md)：实施身份联合验证
  - **AWS 资源:** [要求人类用户通过与身份提供者联合身份验证，并使用临时凭证访问 AWS](https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html)
  - **AWS Well-Architected 指南:** [SEC02-BP04 依赖集中式身份提供商](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_identity_provider.html)<br />[SEC03-BP01 定义访问要求](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_permissions_define.html)

- **除非重新验证，否则对系统和应用程序的特权访问权限将在 12 个月后自动禁用。**
  - **实施指导:** [主题 4：管理身份](theme-4.md)：实施身份联合验证 / **AWS 资源:** [要求人类用户通过与身份提供者联合身份验证，并使用临时凭证访问 AWS](https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html) / **AWS Well-Architected 指南:** [SEC02-BP04 依赖集中式身份提供商](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_identity_provider.html)
  - **实施指导:** [主题 4：管理身份](theme-4.md)：轮换凭证 / **AWS 资源:** [要求工作负载使用 IAM 角色进行访问 AWS](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html)<br />[自动删除未使用的 IAM 角色](https://aws.amazon.com/blogs/security/how-to-centralize-findings-and-automate-deletion-for-unused-iam-roles/)<br />[对于需要长期凭证的用例，定期轮换访问密钥](https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/automatically-rotate-iam-user-access-keys-at-scale-with-aws-organizations-and-aws-secrets-manager.html)<br />[AWS 2023 年澳新银行峰会：您的云端临时证书之旅](https://www.youtube.com/watch?v=jZnh9U-TA6Q)（YouTube视频） / **AWS Well-Architected 指南:** [SEC02-定期BP05 审核和轮换证书](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_audit.html)

- **对系统和应用程序的特权访问权限将在 45 天非活动状态后自动禁用。**
  - **实施指导:** [主题 4：管理身份](theme-4.md)：实施身份联合验证<br />[主题 4：管理身份](theme-4.md)：轮换凭证
  - **AWS 资源:** [要求人类用户与身份提供商联合使用临时 AWS 证书进行访问](https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html)<br />[要求工作负载使用 IAM 角色进行访问 AWS](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html)<br />[自动删除未使用的 IAM 角色](https://aws.amazon.com/blogs/security/how-to-centralize-findings-and-automate-deletion-for-unused-iam-roles/)<br />[对于需要长期凭证的用例，定期轮换访问密钥](https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/automatically-rotate-iam-user-access-keys-at-scale-with-aws-organizations-and-aws-secrets-manager.html)<br />[AWS 2023 年澳新银行峰会：您的云端临时证书之旅](https://www.youtube.com/watch?v=jZnh9U-TA6Q)（YouTube视频）
  - **AWS Well-Architected 指南:** [SEC02-BP04 依赖集中式身份提供商](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_identity_provider.html)<br />[SEC02-定期BP05 审核和轮换证书](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_audit.html)

- **对系统和应用程序的特权访问权限仅限于用户和服务履行职责所需的权限。**
  - **实施指导:** [主题 4：管理身份](theme-4.md)：应用最低权限许可
  - **AWS 资源:** [保护您的 root 用户凭证，不要将其用于日常任务](https://docs.aws.amazon.com/IAM/latest/UserGuide/root-user-best-practices.html)<br />[使用 IAM 访问分析器根据访问活动生成最低权限策略](https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/dynamically-generate-an-iam-policy-with-iam-access-analyzer-by-using-step-functions.html)<br />[使用 IAM Access Analyzer 验证公共和跨账户对资源的访问权限](https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-getting-started.html)<br />[使用 IAM 访问权限分析器验证您的 IAM 策略，以确保权限的安全性和功能性](https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-policy-validation.html)<br />[跨多个账户建立权限防护栏](https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/organizations.html)<br />[使用权限边界设置基于身份的策略可以授予的最大权限](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html)<br />[使用 IAM 策略中的条件进一步限制访问权限](https://aws.amazon.com/blogs/apn/top-recommendations-for-working-with-iam-from-our-aws-heroes-part-3-permissions-boundaries-and-conditions/)<br />[定期审查并删除未使用的用户、角色、权限、策略和证书](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_last-accessed.html)<br />[开始使用 AWS 托管策略，转向最低权限权限](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_job-functions.html)<br />[使用 IAM Identity Center 中的权限集功能](https://docs.aws.amazon.com/singlesignon/latest/userguide/permissionsetsconcept.html)
  - **AWS Well-Architected 指南:** [SEC01-BP02 安全账户 root 用户和属性](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_securely_operate_aws_account.html)<br />[SEC03-BP02 授予最低权限访问权限](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_permissions_least_privileges.html)

- **禁止特权账户访问互联网、电子邮件和 Web 服务。**
  - **实施指导:** 请参阅[技术示例：限制管理权限](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/small-business-cyber-security/small-business-cloud-security-guide/technical-example-restrict-administrative-privileges)（ACSC 网站）
  - **AWS 资源:** 考虑实施 SCP，以[阻止还没有互联网访问权的任何 VPC 获取它](https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examples_vpc.html#example_vpc_2)
  - **AWS Well-Architected 指南:** 不适用

- **特权用户使用不同的特权和非特权操作环境。**
  - **实施指导:** [主题 5：建立数据边界](theme-5.md)
  - **AWS 资源:** [建立数据边界。](https://docs.aws.amazon.com/whitepapers/latest/building-a-data-perimeter-on-aws/building-a-data-perimeter-on-aws.html)考虑在不同数据分类（例如 OFFICIAL:SENSITIVE 或 PROTECTED）或不同风险级别（例如开发、测试或生产）的环境之间实施数据边界。
  - **AWS Well-Architected 指南:** [SEC06-BP03 减少手动管理和交互式访问](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_protect_compute_reduce_manual_management.html)

- **特权操作环境不会在非特权操作环境中进行虚拟化。**

- **非特权账户无法登录到特权操作环境。**

- **特权账户（不包括本地管理员账户）无法登录到非特权操作环境。**

- **Just-in-time 管理用于管理系统和应用程序。**
  - **实施指导:** [主题 4：管理身份](theme-4.md)：实施身份联合验证
  - **AWS 资源:** [要求人类用户与身份提供商联合使用临时 AWS 证书进行访问](https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html)<br />[对您的 AWS 环境实施临时提升访问权限](https://aws.amazon.com/blogs/security/managing-temporary-elevated-access-to-your-aws-environment/)（AWS 博客文章）
  - **AWS Well-Architected 指南:** [SEC02-BP04 依赖集中式身份提供商](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_identity_provider.html)

- **管理活动通过跳转服务器进行。**
  - **实施指导:** [主题 1：使用托管服务](theme-1.md)<br />[主题 3：通过自动化管理可变基础设施](theme-3.md)：使用自动化而不是手动流程
  - **AWS 资源:** 使用[会话管理器](https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager.html)或[运行命令](https://docs.aws.amazon.com/systems-manager/latest/userguide/run-command.html)而不是直接访问 SSH 或 RDP
  - **AWS Well-Architected 指南:** [SEC01-BP05 缩小安全管理范围](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_securely_operate_reduce_management_scope.html)<br />[SEC06-BP03 减少手动管理和交互式访问](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_protect_compute_reduce_manual_management.html)

- **本地管理员账户和服务账户的凭证是唯一的、不可预测的和托管的。**
  - **实施指导:** 请参阅[技术示例：限制管理权限](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/small-business-cyber-security/small-business-cloud-security-guide/technical-example-restrict-administrative-privileges)（ACSC 网站）
  - **AWS 资源:** 不适用
  - **AWS Well-Architected 指南:** 不适用

- **Windows Defender Credential Guard 和 Windows Defender Remote Credential Guard 已启用。**

- **特权访问的使用情况会集中记录并受到保护，防止未经授权的修改和删除，监控泄露迹象，并在检测到网络安全事件时采取行动。**
  - **实施指导:** [主题 7：集中记录和监控](theme-7.md)：启用日志记录<br />[主题 7：集中记录和监控](theme-7.md)：集中日志
  - **AWS 资源:** [使用 CloudWatch 代理将操作系统级别的日志发布到日志 CloudWatch ](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Install-CloudWatch-Agent.html)<br />[ CloudTrail 为您的组织启用](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html)<br />[将 CloudWatch 日志集中到账户中以进行审计和分析](https://aws.amazon.com/blogs/architecture/stream-amazon-cloudwatch-logs-to-a-centralized-account-for-audit-and-analysis/)（AWS 博客文章）<br />[集中管理 Amazon Inspector](https://docs.aws.amazon.com/inspector/latest/user/managing-multiple-accounts.html)<br />[集中管理 Security Hub CSPM](https://docs.aws.amazon.com/securityhub/latest/userguide/designate-orgs-admin-account.html)<br />[Create an organisation-wide aggregator in AWS Config](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html)（AWS 博客文章）<br />[集中管理 GuardDuty](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_organizations.html)<br />[考虑使用 Amazon Security Lake](https://docs.aws.amazon.com/security-lake/latest/userguide/what-is-security-lake.html)<br />[接收来自多个账户的 CloudTrail 日志](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-receive-logs-from-multiple-accounts.html)<br />[向日志归档账户发送日志](https://docs.aws.amazon.com/whitepapers/latest/organizing-your-aws-environment/security-ou-and-accounts.html#log-archive-account)
  - **AWS Well-Architected 指南:** [SEC04-BP01 配置服务和应用程序日志](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_detect_investigate_events_app_service_logging.html)<br />[SEC04-在标准化位置BP02 捕获日志、发现结果和指标](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_detect_investigate_events_logs.html)

- **对特权账户和组的更改会集中记录并受到保护，防止未经授权的修改和删除，监控泄露迹象，并在检测到网络安全事件时采取行动。**

