SV-254240r1210253_rule
V-254240
SRG-OS-000480-GPOS-00227
WN22-00-000030
CAT I
10
Establish a policy, at minimum, to prohibit administrative accounts from using applications that access public-facing networks or the internet, such as web browsers, or applications with potential internet sources, such as email.
Ensure the policy is enforced by technical means, such as allow listing via AppLocker or SRPs.
Document any exceptions to technical enforcement with the ISSO.
Determine whether organization policy, at a minimum, prohibits administrative accounts from using applications that access the internet or other public-facing networks. These applications include web browsers or applications with potential internet sources, such as email, except as necessary for local service administration.
The policy must define specific exceptions for local service administration. These exceptions may include HTTP(S)-based tools that are used for the administration of the local system, services, or attached devices.
Determine whether the organization uses technical means, such as allow listing via AppLocker or Software Restriction Policies (SRPs), to prevent administrative accounts' use of browsers and email applications.
Note: Allow list tools facilitate defining rules that explicitly permit approved applications to run while blocking all others by default.
Administrative accounts that do not have technical restrictions to applications that access public-facing networks must be documented and approved by the information system security officer (ISSO) or AO.
If administrative access to applications that access public-facing networks is not blocked by technical means (except as approved by the AO), this is a finding.
V-254240
False
WN22-00-000030
Determine whether organization policy, at a minimum, prohibits administrative accounts from using applications that access the internet or other public-facing networks. These applications include web browsers or applications with potential internet sources, such as email, except as necessary for local service administration.
The policy must define specific exceptions for local service administration. These exceptions may include HTTP(S)-based tools that are used for the administration of the local system, services, or attached devices.
Determine whether the organization uses technical means, such as allow listing via AppLocker or Software Restriction Policies (SRPs), to prevent administrative accounts' use of browsers and email applications.
Note: Allow list tools facilitate defining rules that explicitly permit approved applications to run while blocking all others by default.
Administrative accounts that do not have technical restrictions to applications that access public-facing networks must be documented and approved by the information system security officer (ISSO) or AO.
If administrative access to applications that access public-facing networks is not blocked by technical means (except as approved by the AO), this is a finding.
M
5485