STIGQter STIGQter: STIG Summary: Network WLAN Bridge Management Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 25 Oct 2023:

The network device must enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level in accordance with applicable policy for the device.

DISA Rule

SV-243176r879530_rule

Vulnerability Number

V-243176

Group Title

SRG-APP-000033-NDM-000212

Rule Version

WLAN-ND-000700

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure authorized accounts with the least privilege rule. Each user will have access to only the privileges they require to perform their assigned duties.

Check Contents

Review the accounts authorized for access to the network device. Determine if the accounts are assigned the lowest privilege level necessary to perform assigned duties. User accounts must be set to a specific privilege level, which can be mapped to specific commands or a group of commands. Authorized accounts should have the least privilege level unless deemed necessary for assigned duties.

If authorized accounts are assigned to greater privileges than necessary, this is a finding.

Vulnerability Number

V-243176

Documentable

False

Rule Version

WLAN-ND-000700

Severity Override Guidance

Review the accounts authorized for access to the network device. Determine if the accounts are assigned the lowest privilege level necessary to perform assigned duties. User accounts must be set to a specific privilege level, which can be mapped to specific commands or a group of commands. Authorized accounts should have the least privilege level unless deemed necessary for assigned duties.

If authorized accounts are assigned to greater privileges than necessary, this is a finding.

Check Content Reference

M

Target Key

5393