Access to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
DISA Rule
SV-253523r1043176_rule
Vulnerability Number
V-253523
Group Title
SRG-APP-000023-CTR-000055
Rule Version
CNTR-PC-000030
Severity
CAT II
CCI(s)
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000016 - Automatically remove or disable temporary and emergency accounts after an organization-defined time-period for each type of account.
- CCI-000017 - Disable accounts when the accounts have been inactive for the organization-defined time-period.
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-000048 - Display an organization-defined system use notification message or banner to users before granting access to the system that provides privacy and security notices consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidelines.
- CCI-000050 - Retain the notification message or banner on the screen until users acknowledge the usage conditions and take explicit actions to log on to or further access the system.
- CCI-004066 - For password-based authentication, enforce organization-defined composition and complexity rules.
- CCI-004061 - For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
- CCI-000213 - Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-000766 - Implement multifactor authentication for network access to non-privileged accounts.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-004045 - Require users to be individually authenticated before granting access to the shared accounts or resources.
- CCI-002145 - Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
Weight
10
Fix Recommendation
Configure Prisma Cloud Console for SAML-based authentication in which the SAML IdP enforces multifactor authentication (e.g., x509/smartcard authentication).
Navigate to Prisma Cloud Compute Console's Manage >> Authentication >> Identity Providers:
- Click "Add provider".
- For Protocol, select "SAML".
- For Identity provider, select provider.
- Configure the settings and click "Save".
SAML settings = Enabled
Configure an SAML identity provider that enforces privileged account multifactor authentication for the Prisma Cloud Compute service provider.
Check Contents
Confirm the Prisma Cloud Console has been configured from SAML-based authentication.
Navigate to Prisma Cloud Compute Console's Manage >> Authentication >> Identity Providers tab.
Verify SAML settings are "Enabled" and an identity provider has been configured.
If SAML settings are not enabled and an identity provider has not been configured, this is a finding.
Vulnerability Number
V-253523
Documentable
False
Rule Version
CNTR-PC-000030
Severity Override Guidance
Confirm the Prisma Cloud Console has been configured from SAML-based authentication.
Navigate to Prisma Cloud Compute Console's Manage >> Authentication >> Identity Providers tab.
Verify SAML settings are "Enabled" and an identity provider has been configured.
If SAML settings are not enabled and an identity provider has not been configured, this is a finding.
Check Content Reference
M
Target Key
5473