

本文為英文版的機器翻譯版本，如內容有任何歧義或不一致之處，概以英文版為準。

# 限制管理權限
<a name="restrict-administrative-privileges"></a>


****  


- **首次請求時，系統會驗證對系統和應用程式的特權存取請求。**
  - **實作指引:** [佈景主題 4：管理身分](theme-4.md)：實作聯合身分
  - **AWS 資源:** [要求人類使用者與身分提供者聯合 AWS 使用臨時憑證存取](https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html)
  - **AWS Well-Architected 指引:** [SEC02-BP04 仰賴集中式身分提供者](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_identity_provider.html)<br />[SEC03-BP01 定義存取需求](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_permissions_define.html)

- **除非重新驗證，否則系統與應用程式的權限存取會在 12 個月後自動停用。**
  - **實作指引:** [佈景主題 4：管理身分](theme-4.md)：實作聯合身分 / **AWS 資源:** [要求人類使用者與身分提供者聯合 AWS 使用臨時憑證存取](https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html) / **AWS Well-Architected 指引:** [SEC02-BP04 仰賴集中式身分提供者](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_identity_provider.html)
  - **實作指引:** [佈景主題 4：管理身分](theme-4.md)：輪換登入資料 / **AWS 資源:** [要求工作負載使用 IAM 角色來存取 AWS](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html)<br />[自動化刪除未使用的 IAM 角色](https://aws.amazon.com/blogs/security/how-to-centralize-findings-and-automate-deletion-for-unused-iam-roles/)<br />[針對需要長期憑證的使用案例，定期輪換存取金鑰](https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/automatically-rotate-iam-user-access-keys-at-scale-with-aws-organizations-and-aws-secrets-manager.html)<br />[AWS Summit ANZ 2023：您前往雲端臨時登入資料的旅程 ](https://www.youtube.com/watch?v=jZnh9U-TA6Q)(YouTube 影片） / **AWS Well-Architected 指引:** [SEC02-BP05 定期稽核和輪換憑證](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_audit.html)

- **系統與應用程式的權限存取會在閒置 45 天後自動停用。**
  - **實作指引:** [佈景主題 4：管理身分](theme-4.md)：實作聯合身分<br />[佈景主題 4：管理身分](theme-4.md)：輪換登入資料
  - **AWS 資源:** [要求人類使用者與身分提供者聯合 AWS 使用臨時憑證存取](https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html)<br />[要求工作負載使用 IAM 角色來存取 AWS](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles.html)<br />[自動化刪除未使用的 IAM 角色](https://aws.amazon.com/blogs/security/how-to-centralize-findings-and-automate-deletion-for-unused-iam-roles/)<br />[針對需要長期憑證的使用案例，定期輪換存取金鑰](https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/automatically-rotate-iam-user-access-keys-at-scale-with-aws-organizations-and-aws-secrets-manager.html)<br />[AWS Summit ANZ 2023：您前往雲端臨時登入資料的旅程 ](https://www.youtube.com/watch?v=jZnh9U-TA6Q)(YouTube 影片）
  - **AWS Well-Architected 指引:** [SEC02-BP04 仰賴集中式身分提供者](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_identity_provider.html)<br />[SEC02-BP05 定期稽核和輪換憑證](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_audit.html)

- **系統和應用程式的特權存取僅限於使用者和服務履行其職責所需的內容。**
  - **實作指引:** [佈景主題 4：管理身分](theme-4.md)：套用最低權限許可
  - **AWS 資源:** [保護您的根使用者憑證，不要將其用於日常任務](https://docs.aws.amazon.com/IAM/latest/UserGuide/root-user-best-practices.html)<br />[使用 IAM Access Analyzer 根據存取活動產生最低權限政策](https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/dynamically-generate-an-iam-policy-with-iam-access-analyzer-by-using-step-functions.html)<br />[使用 IAM Access Analyzer 驗證對 資源的公有和跨帳戶存取權](https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-getting-started.html)<br />[使用 IAM Access Analyzer 驗證您的 IAM 政策是否有安全且功能正常的許可](https://docs.aws.amazon.com/IAM/latest/UserGuide/access-analyzer-policy-validation.html)<br />[跨多個帳戶建立許可護欄](https://docs.aws.amazon.com/prescriptive-guidance/latest/security-reference-architecture/organizations.html)<br />[使用許可界限來設定身分型政策可授予的最大許可](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html)<br />[使用 IAM 政策中的條件進一步限制存取](https://aws.amazon.com/blogs/apn/top-recommendations-for-working-with-iam-from-our-aws-heroes-part-3-permissions-boundaries-and-conditions/)<br />[定期檢閱和移除未使用的使用者、角色、許可、政策和登入資料](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_last-accessed.html)<br />[開始使用 AWS 受管政策並邁向最低權限許可](https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_job-functions.html)<br />[使用 IAM Identity Center 中的許可集功能](https://docs.aws.amazon.com/singlesignon/latest/userguide/permissionsetsconcept.html)
  - **AWS Well-Architected 指引:** [SEC01-BP02 安全帳戶根使用者和屬性](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_securely_operate_aws_account.html)<br />[SEC03-BP02 授予最低權限存取權](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_permissions_least_privileges.html)

- **特殊權限帳戶無法存取網際網路、電子郵件和 Web 服務。**
  - **實作指引:** 請參閱[技術範例：限制管理權限 ](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/small-business-cyber-security/small-business-cloud-security-guide/technical-example-restrict-administrative-privileges)(ACSC 網站）
  - **AWS 資源:** 考慮實作 SCP，[以防止任何尚未擁有網際網路存取權的 VPC 取得它](https://docs.aws.amazon.com/organizations/latest/userguide/orgs_manage_policies_scps_examples_vpc.html#example_vpc_2)
  - **AWS Well-Architected 指引:** 不適用

- **特殊權限使用者使用不同的特殊權限和無特殊權限操作環境。**
  - **實作指引:** [佈景主題 5：建立資料周邊](theme-5.md)
  - **AWS 資源:** [建立資料周邊。](https://docs.aws.amazon.com/whitepapers/latest/building-a-data-perimeter-on-aws/building-a-data-perimeter-on-aws.html)考慮在不同資料分類的環境之間實作資料周邊，例如 OFFICIAL:SENSITIVE或 PROTECTED，或不同的風險層級，例如開發、測試或生產。
  - **AWS Well-Architected 指引:** [SEC06-BP03 減少手動管理和互動式存取](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_protect_compute_reduce_manual_management.html)

- **特殊權限操作環境不會在無特殊權限的操作環境中虛擬化。**

- **無權限帳戶無法登入有權限的操作環境。**

- **特殊權限帳戶 （本機管理員帳戶除外） 無法登入無特殊權限的操作環境。**

- **Just-in-time管理用於管理系統和應用程式。**
  - **實作指引:** [佈景主題 4：管理身分](theme-4.md)：實作聯合身分
  - **AWS 資源:** [要求人類使用者使用臨時憑證與身分提供者聯合 AWS 存取](https://docs.aws.amazon.com/singlesignon/latest/userguide/manage-your-identity-source.html)<br />[實作對您 AWS 環境的暫時提升存取](https://aws.amazon.com/blogs/security/managing-temporary-elevated-access-to-your-aws-environment/) (AWS 部落格文章）
  - **AWS Well-Architected 指引:** [SEC02-BP04 仰賴集中式身分提供者](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_identities_identity_provider.html)

- **管理活動是透過跳轉伺服器執行。**
  - **實作指引:** [主題 1：使用 受管服務](theme-1.md)<br />[佈景主題 3：使用自動化管理可變基礎設施](theme-3.md)：使用自動化而非手動程序
  - **AWS 資源:** 使用 [Session Manager](https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager.html) 或 [Run Command](https://docs.aws.amazon.com/systems-manager/latest/userguide/run-command.html) 而非直接 SSH 或 RDP 存取
  - **AWS Well-Architected 指引:** [SEC01-BP05 減少安全管理範圍](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_securely_operate_reduce_management_scope.html)<br />[SEC06-BP03 減少手動管理和互動式存取](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_protect_compute_reduce_manual_management.html)

- **本機管理員帳戶和服務帳戶的登入資料是唯一、無法預測和管理的。**
  - **實作指引:** 請參閱[技術範例：限制管理權限 ](https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/small-business-cyber-security/small-business-cloud-security-guide/technical-example-restrict-administrative-privileges)(ACSC 網站）
  - **AWS 資源:** 不適用
  - **AWS Well-Architected 指引:** 不適用

- **Windows Defender Credential Guard 和 Windows Defender Remote Credential Guard已啟用。**

- **系統會集中記錄並保護特殊權限存取的使用，避免未經授權的修改和刪除、監控入侵跡象，以及在偵測到網路安全事件時採取動作。**
  - **實作指引:** [佈景主題 7：集中記錄和監控](theme-7.md)：啟用記錄<br />[佈景主題 7：集中記錄和監控](theme-7.md)：集中日誌
  - **AWS 資源:** [使用 CloudWatch Agent 將作業系統層級日誌發佈至 CloudWatch Logs](https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Install-CloudWatch-Agent.html)<br />[為您的組織啟用 CloudTrail ](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html)<br />[在 帳戶中集中 CloudWatch Logs 以進行稽核和分析 ](https://aws.amazon.com/blogs/architecture/stream-amazon-cloudwatch-logs-to-a-centralized-account-for-audit-and-analysis/)(AWS 部落格文章）<br />[集中管理 Amazon Inspector](https://docs.aws.amazon.com/inspector/latest/user/managing-multiple-accounts.html)<br />[集中管理 Security Hub CSPM](https://docs.aws.amazon.com/securityhub/latest/userguide/designate-orgs-admin-account.html)<br />在 (AWS 部落格文章） [中建立整個組織的彙整工具 AWS Config](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/creating-trail-organization.html) <br />[集中管理 GuardDuty](https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_organizations.html)<br />[考慮使用 Amazon Security Lake](https://docs.aws.amazon.com/security-lake/latest/userguide/what-is-security-lake.html)<br />[從多個帳戶接收 CloudTrail 日誌](https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-receive-logs-from-multiple-accounts.html)<br />[將日誌傳送至日誌封存帳戶](https://docs.aws.amazon.com/whitepapers/latest/organizing-your-aws-environment/security-ou-and-accounts.html#log-archive-account)
  - **AWS Well-Architected 指引:** [SEC04-BP01 設定服務和應用程式日誌記錄](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_detect_investigate_events_app_service_logging.html)<br />[SEC04-BP02 在標準化位置中擷取日誌、調查結果和指標](https://docs.aws.amazon.com/wellarchitected/latest/security-pillar/sec_detect_investigate_events_logs.html)

- **系統會集中記錄特殊權限帳戶和群組的變更，並防止未經授權的修改和刪除、監控入侵跡象，以及在偵測到網路安全事件時採取動作。**

