Are you tracking root logins in AWS?

Share this post

AWS Root Login
AWS Root Login

The root account in AWS is the master key to all of your organization’s cloud-hosted systems, activities, and services. If an attacker gets in: game over. It must be well-protected.

A properly configured AWS setup will require very infrequent root logins. Most responsibilities should be doled out to other users with fewer permissions. The root account should not be used for making changes to your organization’s environment. It’s important to track root usage of your organization but some may think this is an easy chore to overlook because of it’s low usage. However, even with infrequent logins, tracking the behavior of the root account is an easily achievable task.

Root logins, attempts, and failures can be tracked with AWS CloudTrail. Users can also set up email notifications for the email address connected to the root account, so the owner can be quickly notified if someone tries to access the root account. Root login attempts should be actively monitored, and very few alerts should ever come through, because people should not be using the root account often if at all for production or business operations. 

AWS provides documentation to help users in setting these alerts up. We suggest implementing this ASAP!

Want to get great cybersecurity content delivered to your inbox? Click here to sign up for our monthly newsletter, Tales from the Click.

Eloghosa Obasuyi
Eloghosa was a cybersecurity analyst at Fractional CISO from 2021-2022. He graduated from Columbus State University in Georgia in 2021. In college, he studied cybersecurity and has been honing his cyber skills for years through practice competing at capture-the-flag, cyber defense, and penetration testing events. Eloghosa is an AWS Certified Cloud Practitioner and is Security+ certified. Today, Eloghosa works at AWS as a Cloud Support Engineer – Security.

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales