STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

Information Assurance - System Access Control Records (DD Form 2875 or equivalent)

DISA Rule

SV-245775r1226291_rule

Vulnerability Number

V-245775

Group Title

IA-05.02.01

Rule Version

IA-05.02.01

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Written procedures for personnel who request access to a computer system must be developed.

2. A SAAR form (DD Form 2875 or equivalent) must be used to define and control individual access for systems. If applicable, the most current version of the DD Form 2875 SAAR must be used for ALL NEW account requests. Note: This is not a mandate to update previously processed account request forms to the most current version. Locally developed or service-level forms may also be used if the same information found on the DD Form 2875 is used.

3. Local or service-level SAAR forms must minimally contain appropriate information for checking compliance with security requirements for privileged, routine user, Classified, and Unclassified systems access as on the DD Form 2875.
Information required:
a. Identification of the individual requesting access.
b. Signature dates.
c. Investigation level and security clearance required of the system for which access is being requested.
d. Investigation and security clearance of the individual requesting access.
e. Supervisory approval of the individual requesting access.
f. Security manager approval of the individual requesting access.
g. ISSO approval (or appointee) of the office responsible for approving access to the system being requested.
h. Information system owner approval (or appointee) of the office responsible for approving access to the system being requested
i. Ensure all appropriate IA training was completed for the systems to which personnel are requesting access.

4. A separate "User Agreement" must be signed by each user before access is granted. This includes both system "users" and "privileged account holders" (system administrators). For privileged users, a signed Privileged Access Statement IAW Appendix 4 of DOD 8570.01-M, Information Assurance Workforce Improvement Program, is required.

Check Contents

1. Check to ensure there are written procedures for personnel who request access to a computer system.

2. Note in the report finding details which access form is used (locally developed, service-level, or DD Form 2875).

3. If applicable, ensure the most current version of the DD Form 2875 (System Authorization Access Request [SAAR]) is being used for all new account requests. Note: This is not a mandate to update previously processed account request forms to the most current version.

4. Note what training is required/conducted before system access is granted.

5. Review a sample of system access request forms to ensure the forms contain appropriate information for checking compliance with security requirements for privileged, user, Classified, and Unclassified systems access.
Information required:
a. Identification of the individual requesting access.
b. Signature dates.
c. Investigation level and security clearance required of the system to which access is being requested.
d. Investigation and security clearance of the individual requesting access.
e. Supervisory approval of the individual requesting access.
f. Security manager approval of the individual requesting access.
g. ISSO approval (or appointee) of the office responsible for approving access to the system being requested.
h. Information system owner approval (or appointee) of the office responsible for approving access to the system being requested.
i. Ensure all appropriate Information Assurance (IA) training was completed for the systems to which personnel are requesting access.

6. Check to ensure a separate "User Agreement" also exists for both system "users" and "privileged account holders" (system administrators). For privileged users, a signed Privileged Access Statement IAW Appendix 4 of DOD 8570.01-M, Information Assurance Workforce Improvement Program, is required.

7. In a tactical environment, the forms used to control systems access might not be readily accessible in the field. Determine where the forms are maintained and, if the location is not within reach, attempt to obtain a sample copy of a completed form via fax, email, etc. Fixed locations with assigned IA staff should have the forms available.

Vulnerability Number

V-245775

Documentable

False

Rule Version

IA-05.02.01

Severity Override Guidance

1. Check to ensure there are written procedures for personnel who request access to a computer system.

2. Note in the report finding details which access form is used (locally developed, service-level, or DD Form 2875).

3. If applicable, ensure the most current version of the DD Form 2875 (System Authorization Access Request [SAAR]) is being used for all new account requests. Note: This is not a mandate to update previously processed account request forms to the most current version.

4. Note what training is required/conducted before system access is granted.

5. Review a sample of system access request forms to ensure the forms contain appropriate information for checking compliance with security requirements for privileged, user, Classified, and Unclassified systems access.
Information required:
a. Identification of the individual requesting access.
b. Signature dates.
c. Investigation level and security clearance required of the system to which access is being requested.
d. Investigation and security clearance of the individual requesting access.
e. Supervisory approval of the individual requesting access.
f. Security manager approval of the individual requesting access.
g. ISSO approval (or appointee) of the office responsible for approving access to the system being requested.
h. Information system owner approval (or appointee) of the office responsible for approving access to the system being requested.
i. Ensure all appropriate Information Assurance (IA) training was completed for the systems to which personnel are requesting access.

6. Check to ensure a separate "User Agreement" also exists for both system "users" and "privileged account holders" (system administrators). For privileged users, a signed Privileged Access Statement IAW Appendix 4 of DOD 8570.01-M, Information Assurance Workforce Improvement Program, is required.

7. In a tactical environment, the forms used to control systems access might not be readily accessible in the field. Determine where the forms are maintained and, if the location is not within reach, attempt to obtain a sample copy of a completed form via fax, email, etc. Fixed locations with assigned IA staff should have the forms available.

Check Content Reference

M

Target Key

5410