STIGQter STIGQter: STIG Summary: Microsoft Windows PAW Security Technical Implementation Guide Version: 3 Release: 3 Benchmark Date: 01 Apr 2026:

Administrators of high-value IT resources must complete required training.

DISA Rule

SV-243442r991589_rule

Vulnerability Number

V-243442

Group Title

SRG-OS-000480-GPOS-00227

Rule Version

WPAW-00-000100

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Add the following topics to initial and annual update training modules for system administrators of high-value IT resources:

- Remotely manage high-value IT resources only via a PAW.
- Administrative accounts will not be used for non-administrative functions (for example, read email, browse Internet).

Check Contents

Review site training records and verify the organization's system administrators of high-value IT resources have received the following initial and annual training:

- Remotely manage high-value IT resources only via a PAW.
- Administrative accounts will not be used for non-administrative functions (for example, read email, browse Internet).

If required training has not been completed by the organization's system administrators of high-value IT resources, this is a finding.

Vulnerability Number

V-243442

Documentable

False

Rule Version

WPAW-00-000100

Severity Override Guidance

Review site training records and verify the organization's system administrators of high-value IT resources have received the following initial and annual training:

- Remotely manage high-value IT resources only via a PAW.
- Administrative accounts will not be used for non-administrative functions (for example, read email, browse Internet).

If required training has not been completed by the organization's system administrators of high-value IT resources, this is a finding.

Check Content Reference

M

Target Key

5405