The ICS must be configured to prevent nonprivileged users from executing privileged functions.
DISA Rule
SV-258600r997506_rule
Vulnerability Number
V-258600
Group Title
SRG-APP-000340-NDM-000288
Rule Version
IVCS-NM-000050
Severity
CAT I
CCI(s)
- CCI-000163 - Protect audit information from unauthorized modification.
- CCI-000164 - Protect audit information from unauthorized deletion.
- CCI-000166 - Provide irrefutable evidence that an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-000213 - Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
- CCI-000345 - Enforce logical access restrictions associated with changes to the system.
- CCI-000366 - Implement the security configuration settings.
- CCI-000370 - Manage configuration settings for organization-defined system components using organization-defined automated mechanisms.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-004045 - Require users to be individually authenticated before granting access to the shared accounts or resources.
- CCI-001199 - Protects the confidentiality and/or integrity of organization-defined information at rest.
- CCI-001493 - Protect audit tools from unauthorized access.
- CCI-001495 - Protect audit tools from unauthorized deletion.
- CCI-001499 - Limit privileges to change software resident within software libraries.
- CCI-003980 - Allow user installation of software only with explicit privileged status.
- CCI-001813 - Enforce access restrictions using organization-defined mechanisms.
- CCI-002169 - Enforce a role-based access control policy over defined subjects and objects based upon organization-defined roles and users authorized to assume such roles.
- CCI-002235 - Prevent non-privileged users from executing privileged functions.
- CCI-002883 - Restrict the use of maintenance tools to authorized personnel only.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-003628 - Disable accounts when the accounts are no longer associated to a user.
- CCI-003831 - Alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information.
- CCI-004046 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
- CCI-004047 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that the device meets organization-defined strength of mechanism requirements.
- CCI-004058 - For password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.
- CCI-004059 - For password-based authentication, update the list of passwords on an organization-defined frequency.
- CCI-004060 - For password-based authentication, update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly.
- CCI-004061 - For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
- CCI-004063 - For password-based authentication, require immediate selection of a new password upon account recovery.
- CCI-004064 - For password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters.
- CCI-004065 - For password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.
Weight
10
Fix Recommendation
Configure Realms and Roles as needed to meet mission requirements.
Note: The ".Administrators" role is a default role name, other administrator role names can be used. Groups must be used, separate usernames or an allow-all username of * is not acceptable.
In the ICS Web UI, navigate to Administrators >> Admin Realms >> Admin Realms.
1. Click the admin realm that is currently being used on the ICS for administrator logins. By default, it is "Admin Users".
2. In the "General" tab, under Servers >> Directory/Attribute, select the previously configured LDAP Directory. If none is configured, follow vendor supplied instructions for creating an LDAP Authentication Server.
3. In the "Role Mapping" tab, under "when users meet these conditions", select new rule.
4. Under rule based on, select "Group Membership".
5. Give the rule a name.
6. Select "is".
7. Provide the exact group name in the text box. This name must match the "CN=" attribute name. For example, if the group is "CN=ivanti.adm.group" then add the "ivanti.adm.group" to the text box.
8. Under "then assign these roles", select the admin role used by ICS for admin logins. By default this is ".Administrators".
9. Click "Save Changes".
10. Under "Role Mapping", if there are more roles needed for more specific role-based access to the ICS, configure more of them here.
11. Once complete, click "Save Changes".
Check Contents
Verify Realms and Roles are configured as needed to meet mission requirements.
In the ICS Web UI, navigate to Administrators >> Admin Realms >> Admin Realms.
1. Click the admin realm that is currently being used on the ICS for administrator logins. By default, it is "Admin Users".
2. In the "General" tab, under Servers >> Directory/Attribute, verify it does not say "none".
3. In the "Role Mapping" tab, under "when users meet these conditions", verify the following:
- "Group" must be used, and the local site's administrator active directory group must be selected and assigned to the ".Administrators" role. Note that this role could be different if using something other than the default ".Administrators" role.
- Verify separate usernames are not used. Verify an allow-all username of * is used.
If a realm or role is not configured to prevent nonprivileged users from executing privileged functions, this is a finding.
Vulnerability Number
V-258600
Documentable
False
Rule Version
IVCS-NM-000050
Severity Override Guidance
Verify Realms and Roles are configured as needed to meet mission requirements.
In the ICS Web UI, navigate to Administrators >> Admin Realms >> Admin Realms.
1. Click the admin realm that is currently being used on the ICS for administrator logins. By default, it is "Admin Users".
2. In the "General" tab, under Servers >> Directory/Attribute, verify it does not say "none".
3. In the "Role Mapping" tab, under "when users meet these conditions", verify the following:
- "Group" must be used, and the local site's administrator active directory group must be selected and assigned to the ".Administrators" role. Note that this role could be different if using something other than the default ".Administrators" role.
- Verify separate usernames are not used. Verify an allow-all username of * is used.
If a realm or role is not configured to prevent nonprivileged users from executing privileged functions, this is a finding.
Check Content Reference
M
Target Key
5558