STIGQter STIGQter: STIG Summary: ISEC7 Sphere Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

ISEC7 SPHERE must disable or delete local account created during application installation and configuration.

DISA Rule

SV-224767r1013815_rule

Vulnerability Number

V-224767

Group Title

SRG-APP-000148

Rule Version

ISEC-06-000660

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Log in to the ISEC7 SPHERE console.
Navigate to Administration >> Configuration >> Account Management >> Users.
Select "Edit" next to the local account Admin.
Check "Log in disabled" for the account.
Click "Save".

Check Contents

Log in to the ISEC7 SPHERE console.
Navigate to Administration >> Configuration >> Account Management >> Users.
Select "Edit" next to the local account Admin.
Verify "Log in disabled" has been selected.

If "Log in disabled" has not been selected, this is a finding.

Vulnerability Number

V-224767

Documentable

False

Rule Version

ISEC-06-000660

Severity Override Guidance

Log in to the ISEC7 SPHERE console.
Navigate to Administration >> Configuration >> Account Management >> Users.
Select "Edit" next to the local account Admin.
Verify "Log in disabled" has been selected.

If "Log in disabled" has not been selected, this is a finding.

Check Content Reference

M

Target Key

4200