Add unused iam role within 60 days control #663
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Added the control and query to the conformance pack iam.sp file
Associated that control to the Other Checks benchmark.
Closes #662
Note: if the role_last_used_date is null, essentially never used, the logic of the query is consistent with other queries like iam_user_unused_credentials_45 where never used is considered an 'alarm' but handled with a specific reason that it was never used.
I have tested the query, but not the entire benchmark if the control was added correctly