Checks Performed
- OCI IAM Active Users Should Be Members Of At Least One Group
- OCI IAM Admin Full Access Policies Should Have WHERE Conditions
- OCI IAM Admin Group Should Be Protected From Self-Modification
- OCI IAM Admin Users Should Have MFA Enabled
- OCI IAM Admin Users Should Not Have API Signing Keys
- OCI IAM API Keys Should Be Rotated Every 90 Days
- OCI IAM Auth Tokens Should Be Rotated Every 90 Days
- OCI IAM Console Users Should Have MFA Enforced
- OCI IAM Customer Secret Keys Should Be Rotated Every 90 Days
- OCI IAM Instance Principals Should Be Used Instead Of API Keys
- OCI IAM Only Administrators Should Manage All Resources
- OCI IAM Password Policy Should Enforce Strong Requirements
- OCI IAM Password Policy Should Enforce Yearly Rotation
- OCI IAM Password Policy Should Prevent Password Reuse
- OCI IAM Password Policy Should Require Lowercase Characters
- OCI IAM Password Policy Should Require Minimum 14 Characters
- OCI IAM Password Policy Should Require Numeric Characters
- OCI IAM Password Policy Should Require Special Characters
- OCI IAM Password Policy Should Require Uppercase Characters
- OCI IAM Policies Should Grant Permissions To Groups Not Users
- OCI IAM Policies Should Not Grant All Resources Access To Any User
- OCI IAM Policies Should Not Grant Manage/Use On All Resources
- OCI IAM Service Administrator Group Should Be Defined
- OCI IAM Unused User Credentials Should Be Disabled
- OCI IAM Users Should Have MFA Enabled
- OCI IAM Users Should Have Only One Active API Key
- OCI IAM Users Should Have Valid Email Addresses

