SV-256097r1015805_rule
V-256097
SRG-APP-000317-NDM-000282
RINP-DM-000091
CAT II
10
Change the account of last resort to a new password when administrators who know the credential leave the organization. Document this process in the SSP.
Set the password for the account of last resort and/or root as needed based on what the person departing had access to.
Change default system shell account passwords as required:
Go to Configuration >> Appliance Security >> Security Compliance page Accounts section to change or disable the following passwords.
root - Accessible only through SSH from other modules in an Enterprise NetProfiler. This has shell access from the console if login is enabled. Change to implement a DOD-compliant password. Securely store and protect the password.
admin - Accessible only through the console port. This is for initial setup only with no shell access. Recommend use as account of last resort; however, login may be disabled only if another account of last resort is configured. Change to implement a DOD-compliant password. Securely store and protect the password. The following system account must be configured to comply with this requirement.
mazu - Accessible through SSH; this has shell access unless disabled. Disable the password (DOD preferred) or change to implement a DOD-compliant password. Securely store and protect the password.
Review the site's System Security Plan (SSP) to verify the password for the account of last resort and/or the root account are changed when a system administrator with knowledge of the password leaves or no longer has a need to know/access.
If the credentials for the account of last resort are not changed when administrators who know the credential leave the organization, this is a finding.
V-256097
False
RINP-DM-000091
Review the site's System Security Plan (SSP) to verify the password for the account of last resort and/or the root account are changed when a system administrator with knowledge of the password leaves or no longer has a need to know/access.
If the credentials for the account of last resort are not changed when administrators who know the credential leave the organization, this is a finding.
M
5514