IAM Security Reviewer

Evaluate IAM configurations against NIST SP 800-63B/800-53 controls.

6|Updated Oct 25, 2025
One-click install
npx skills add https://github.com/williamzujkowski/cognitive-toolworks --skill iam-security-reviewer
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: IAM Security Reviewer
Source: https://github.com/williamzujkowski/cognitive-toolworks/tree/main/skills/security-iam-reviewer
Command: npx skills add https://github.com/williamzujkowski/cognitive-toolworks --skill iam-security-reviewer

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Identify security gaps in IAM configurations by evaluating MFA, password policy, least-privilege enforcement, and PAM against NIST SP 800-63B/800-53 controls, helping teams tighten access controls before incidents.

Core Features & Use Cases

  • MFA enforcement and privileged-account review to prevent unauthorized access.
  • Password policy and credential management assessment aligned with NIST guidance.
  • Least privilege verification using RBAC/ABAC and PAM readiness for privileged operations.
  • Actionable remediation guidance and policy snippets to improve IAM posture.
  • Use case: pre-deployment IAM audits, post-incident identity reviews, and third-party access assessments.

Quick Start

Run the IAM Security Reviewer with your identity provider and scope to start an IAM security review.

Frequently Asked Questions about IAM Security Reviewer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit IAM configurations for NIST compliance?

Identify IAM security gaps by evaluating MFA, password policy, least-privilege, and PAM controls against NIST SP 800-63B/800-53. Input your identity provider and scope to receive findings, AAL compliance status, and remediation policies.

What is involved in an identity and access management security review?

An IAM security review evaluates MFA enforcement, password policies, least-privilege via RBAC/ABAC, and PAM readiness against NIST controls. It helps tighten access controls across cloud and on-prem identities before incidents occur.

How do I assess MFA and password policy against NIST SP 800-63B?

Assess MFA and password policy against NIST SP 800-63B by specifying the authenticator level (AAL1, AAL2, or AAL3). The review evaluates credential management practices and outputs compliance findings with actionable remediation policies.

Can I use this IAM assessment for cloud and on-prem identity providers?

Yes, IAM security assessments apply to both cloud and on-prem identities. You must provide the identity provider name and can scope the review to authentication, authorization, accounts, or all to evaluate access controls comprehensively.

What is the best way to verify least-privilege enforcement in IAM?

Verify least-privilege enforcement by reviewing RBAC and ABAC configurations alongside PAM readiness for privileged operations. This ensures access rights are minimized and aligned with NIST SP 800-53 security controls.

When do I need to run a privileged-account access review?

Run a privileged-account access review during pre-deployment IAM audits, post-incident identity reviews, or third-party access assessments. It verifies PAM readiness and prevents unauthorized access to critical systems.