STIGQter STIGQter: STIG Summary: NetApp ONTAP DSC 9.x Security Technical Implementation Guide Version: 2 Release: 4 Benchmark Date: 01 Jul 2026:

ONTAP must prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

DISA Rule

SV-246930r961353_rule

Vulnerability Number

V-246930

Group Title

SRG-APP-000340-NDM-000288

Rule Version

NAOT-AC-000009

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure privileged users with "security login create -user-or-group-name <user_name> -role admin".

Configure non-privileged users with "security login create -user-or-group-name <user_name> -role <role_name>“where a non-privileged user role other than admin is used.

Check Contents

Use "security login role show” to see role-based access policies defined in ONTAP for privileged and unprivileged users. Privileged users have the role of admin.

If ONTAP does not prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures, this is a finding.

Vulnerability Number

V-246930

Documentable

False

Rule Version

NAOT-AC-000009

Severity Override Guidance

Use "security login role show” to see role-based access policies defined in ONTAP for privileged and unprivileged users. Privileged users have the role of admin.

If ONTAP does not prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures, this is a finding.

Check Content Reference

M

Target Key

5415