SV-251208r1018617_rule
V-251208
SRG-APP-000378-DB-000365
RD6X-00-007000
CAT II
10
To ensure a regular user is unable to perform updates:
1. Log in to the Redis Enterprise control plane.
2. Navigate to the access controls tab.
3. In the users section, review each users role to ensure they are assigned the appropriate permissions.
4. If a user is not assigned appropriate permissions, ensure they are moved to an appropriate role.
Modules may be added to the Redis Enterprise control plane (adminUI) by navigating to the settings tab and then modules. Only admin users can view the settings tab.
To verify that users without explicit privileged status are not able to install modules, do the following:
1. Log in to the Redis Enterprise control plane (adminUI) with a user with administrative privileges.
2. Navigate to the access control tab.
3. Verify that only organizationally defined users have the appropriate privileges.
If a user is not assigned appropriate permissions, this is a finding.
V-251208
False
RD6X-00-007000
Modules may be added to the Redis Enterprise control plane (adminUI) by navigating to the settings tab and then modules. Only admin users can view the settings tab.
To verify that users without explicit privileged status are not able to install modules, do the following:
1. Log in to the Redis Enterprise control plane (adminUI) with a user with administrative privileges.
2. Navigate to the access control tab.
3. Verify that only organizationally defined users have the appropriate privileges.
If a user is not assigned appropriate permissions, this is a finding.
M
5443