AWSHow-To & HardeningRetrospectives

Quarterly External Access Review Checklist for AWS

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.

External access to your AWS resources should be known and approved. This quarterly review checklist keeps it that way.

Prepare

  • External access analyzers exist in every region, with the organization as the zone of trust.
  • Findings are aggregated in Security Hub or exported for review.
  • A list of approved third-party AWS account IDs (vendors, partners) is maintained with owners.

Review active findings

  • Every public access finding has been either removed or approved by the data owner in writing.
  • Every cross-account finding maps to an approved third-party account.
  • Findings for unknown account IDs are investigated within five business days.
  • Access granted to entire external organizations or wildcard principals is justified.

Review archive rules

  • Archive rules still match current vendor relationships.
  • Vendors whose contracts ended have been removed from archive rules and resource policies.

Review trust policies on IAM roles

  • Roles trusted by third parties use an external ID.
  • Trust policies are scoped to specific principals, not entire accounts where avoidable.
  • Unused third-party roles are deleted.

Unused access

  • Unused roles, keys and passwords older than 90 days are removed.
  • Top ten roles by unused permissions are scheduled for policy refinement.

Record

  • Summary of changes made and approvals obtained.
  • Metrics: open external findings, unused access findings, trend versus last quarter.
aws external access review checklistIAM Access Analyzer2019

More on this story