STIGQter STIGQter: STIG Summary: Network WLAN AP-IG Management Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 25 Oct 2023:

The network device must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-243146r879589_rule

Vulnerability Number

V-243146

Group Title

SRG-APP-000148-NDM-000346

Rule Version

WLAN-ND-001300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the device to allow only one local account of last resort for emergency access and store the credentials in a secure manner.

Check Contents

Review the network device configuration to determine if an authentication server is defined for gaining administrative access. If so, there must be only one account of last resort configured locally for an emergency.

Verify the username and password for the local account of last resort is contained in a sealed envelope kept in a safe.

If an authentication server is used and more than one local account exists, this is a finding.

Vulnerability Number

V-243146

Documentable

False

Rule Version

WLAN-ND-001300

Severity Override Guidance

Review the network device configuration to determine if an authentication server is defined for gaining administrative access. If so, there must be only one account of last resort configured locally for an emergency.

Verify the username and password for the local account of last resort is contained in a sealed envelope kept in a safe.

If an authentication server is used and more than one local account exists, this is a finding.

Check Content Reference

M

Target Key

5391