Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms. Monitoring changes to IAM policies will help ensure authentication and authorization controls remain intact.
Recommended Mitigation
It is recommended that a metric filter and alarm be established changes made to Identity and Access Management (IAM) policies.