SV-220370r961095_rule
V-220370
SRG-APP-000211-DB-000122
ML09-00-004500
CAT II
10
Configure MarkLogic user roles so that only actual Administrators are assigned Administrative roles and each Administrator has an individual account.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users.
4. Remove administrative privileges from general user accounts, and ensure administrators have separate administrative accounts.
Validate MarkLogic User accounts to verify only Administrators have Administrative roles assigned and each Administrator has an individual account.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users. If administrator and general user accounts are not separated, this is a finding.
V-220370
False
ML09-00-004500
Validate MarkLogic User accounts to verify only Administrators have Administrative roles assigned and each Administrator has an individual account.
Perform the check from the MarkLogic Server Admin Interface with a user that holds administrative-level privileges.
1. Click the Security icon.
2. Click the Users icon on the left tree menu.
3. Inspect the Users. If administrator and general user accounts are not separated, this is a finding.
M
4064