Ensure that there is no wildcard resources in an inline IAM group policy

IAM group policy should be setup in such a way that it follows the least privilege principle. Having wildcard in a resource allows specified action on all the resources.

Risk Level: High
Cloud Entity: IAM Group
CloudGuard Rule ID: D9.CFT.IAM.25
Covered by Spectral: No
Category: Security, Identity, & Compliance


AWS_IAM_Group should not have Policies contain-any [ PolicyDocument.Statement contain-any [ Effect = 'Allow' and Resource='*' ] ]


From CFT
Set AWS::IAM::Group Policies.PolicyDocument.Statement.Resource to a specific set of resources.


  1. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-iam-group.html
  2. https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_elements_principal.html

IAM Group

An IAM group is an entity that you create in AWS to represent a group of users. A group can have permissions associated with it.

Compliance Frameworks

  • AWS CloudFormation ruleset