MEDIUM
Source
CloudSploit
ID
iam-role-policies

IAM Role Policies

Ensures IAM role policies are properly scoped with specific permissions

Policies attached to IAM roles should be scoped to least-privileged access and avoid the use of wildcards.

Ensure that all IAM roles are scoped to specific services and API calls.