# Cis AWS Storage 2.8

> Ensure the Creation of IAM Groups

- Skill: `cyberstrikeus/cis-aws-storage-2-8` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-aws-storage-2-8`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-aws-storage-2-8/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-aws-storage-2-8

---


# CIS Control 2.8: Ensure the Creation of IAM Groups (Manual)

## Profile Applicability

- **Level 2**

## Description

IAM Groups are collections of users that share the same permissions for accessing AWS resources. For instance, you can create a group named "Administrators," which includes users who require full access to your AWS environment. This simplifies permission management by assigning common access policies to all members of the group.

## Rationale

IAM groups in AWS simplify permission management by grouping users with similar access needs and applying common access policies, reducing administrative overhead and enhancing security through the principle of least privilege. This approach ensures consistency, scalability, and ease of auditing, strengthening the overall security posture of the AWS environment.

## Audit Procedure

### Via AWS Management Console

1. Enable AWS CloudTrail
2. Review CloudTrail Logs
3. Utilize AWS Config
4. Check IAM Console

### Via AWS CLI

\`\`\`bash
aws iam list-groups
aws iam get-group --group-name <GROUP_NAME>
aws iam list-attached-group-policies --group-name <GROUP_NAME>
\`\`\`

## Remediation

### Via AWS CLI

\`\`\`bash

# Create IAM group

aws iam create-group --group-name Administrators

# Attach policy to group

aws iam attach-group-policy \
 --group-name Administrators \
 --policy-arn arn:aws:iam::aws:policy/AdministratorAccess

# Add user to group

aws iam add-user-to-group \
 --user-name <USERNAME> \
 --group-name Administrators
\`\`\`

## References

1. [Creating IAM Groups](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_groups_create.html)

## CIS Controls

| Controls Version | Control                                              | IG 1 | IG 2 | IG 3 |
| ---------------- | ---------------------------------------------------- | ---- | ---- | ---- |
| v8               | 6.8 Define and Maintain Role-Based Access Control    |      |      | ●    |
| v7               | 16.1 Maintain an Inventory of Authentication Systems |      | ●    | ●    |
| v7               | 16.2 Configure Centralized Point of Authentication   |      | ●    | ●    |

