Dragos Platform must use an Identity Provider (IDP) for authentication and authorization processes.
DISA Rule
SV-270910r1057994_rule
Vulnerability Number
V-270910
Group Title
SRG-APP-000023
Rule Version
DRAG-OT-000090
Severity
CAT II
CCI(s)
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000017 - Disable accounts when the accounts have been inactive for the organization-defined time-period.
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-000766 - Implement multifactor authentication for network access to non-privileged accounts.
- CCI-001084 - Isolate security functions from nonsecurity functions.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
- CCI-002145 - Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.
Weight
10
Fix Recommendation
Configure LDAP.
In the UI, navigate to Admin >> SiteStore Management >> Authentication Providers.
Next to LDAP/Active Directory, click "ADD PROVIDER".
Fill in the configuration in the "Add New LDAP Provider" form.
Click "Save".
Check Contents
Review the authentication method being used by the Platform.
In the UI, navigate to Admin >> SiteStore Management >> Authentication Providers.
If the Platform does not have an Authentication Provider configured, this is a finding.
Vulnerability Number
V-270910
Documentable
False
Rule Version
DRAG-OT-000090
Severity Override Guidance
Review the authentication method being used by the Platform.
In the UI, navigate to Admin >> SiteStore Management >> Authentication Providers.
If the Platform does not have an Authentication Provider configured, this is a finding.
Check Content Reference
M
Target Key
5675