Automation Controller must be configured to use an enterprise user management system.
DISA Rule
SV-256905r1051118_rule
Vulnerability Number
V-256905
Group Title
SRG-APP-000148-AS-000101
Rule Version
APAS-AT-000047
Severity
CAT II
CCI(s)
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-001953 - Accepts Personal Identity Verification-compliant credentials.
- CCI-001954 - Electronically verifies Personal Identity Verification-compliant credentials.
- CCI-004068 - For public key-based authentication, implement a local cache of revocation data to support path discovery and validation.
- CCI-002007 - Prohibit the use of cached authenticators after an organization-defined time period.
- CCI-002009 - Accept Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-002010 - Electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-004083 - Accept only external credentials that are NIST compliant.
- CCI-004085 - Conform to organization-defined identity management profiles for identity management.
Weight
10
Fix Recommendation
Log in to Automation Controller as an administrator and navigate to Settings >> Authentication.
Configure the appropriate authentication provider and associated fields for the organization-defined identity provider:
Click on LDAP settings.
Click "Edit".
Configure/complete the fields.
Click "Save".
Check Contents
The Administrator must check the Automation Controller web administrator console and verify the appropriate authentication provider is configured and the associated fields are complete and accurate.
Log in to Automation Controller as an administrator and navigate to Settings >> Authentication.
If the organization-defined identity provider is not configured, or any associated fields are incomplete or inaccurate, this is a finding.
Vulnerability Number
V-256905
Documentable
False
Rule Version
APAS-AT-000047
Severity Override Guidance
The Administrator must check the Automation Controller web administrator console and verify the appropriate authentication provider is configured and the associated fields are complete and accurate.
Log in to Automation Controller as an administrator and navigate to Settings >> Authentication.
If the organization-defined identity provider is not configured, or any associated fields are incomplete or inaccurate, this is a finding.
Check Content Reference
M
Target Key
5534