Compliance Guardian must provide automated mechanisms for supporting account management functions.
DISA Rule
SV-256842r890136_rule
Vulnerability Number
V-256842
Group Title
SRG-APP-000023
Rule Version
APCG-00-000015
Severity
CAT II
CCI(s)
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000017 - Disable accounts when the accounts have been inactive for the organization-defined time-period.
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-000172 - Generate audit records for the event types defined in AU-2 c that include the audit record content defined in AU-3.
- CCI-001133 - Terminate the network connection associated with a communications session at the end of the session or after an organization-defined time period of inactivity.
- CCI-001682 - Automatically removes or disables emergency accounts after an organization-defined time period for each type of account.
- CCI-002130 - Automatically audit account enabling actions.
- CCI-002145 - Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
- CCI-002361 - Automatically terminate a user session after organization-defined conditions or trigger events requiring session disconnect.
Weight
10
Fix Recommendation
Configure the Compliance Guardian configuration to ensure AD Integration is enabled.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the Authentication Manager section, click "Authentication Manager".
- Navigate to "AD Integration".
- Set the Action of "AD Integration" to "Enable".
- Save settings.
Add AD user or group to Compliance Guardian by Account Manager; realize automated mechanisms through AD account management functions.
Check Contents
Compliance Guardian supports integration with Active Directory (AD) for automated account management.
Check the Compliance Guardian configuration to ensure AD Integration is enabled.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the General Security section, click "Authentication Manager".
- Navigate to "AD Integration".
- Verify that the "AD Integration" option is enabled.
If the AD Integration option is not enabled, this is a finding.
Vulnerability Number
V-256842
Documentable
False
Rule Version
APCG-00-000015
Severity Override Guidance
Compliance Guardian supports integration with Active Directory (AD) for automated account management.
Check the Compliance Guardian configuration to ensure AD Integration is enabled.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the General Security section, click "Authentication Manager".
- Navigate to "AD Integration".
- Verify that the "AD Integration" option is enabled.
If the AD Integration option is not enabled, this is a finding.
Check Content Reference
M
Target Key
5531