Ax-OS must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
DISA Rule
SV-276005r1122665_rule
Vulnerability Number
V-276005
Group Title
SRG-APP-000033
Rule Version
AXOS-00-000025
Severity
CAT II
CCI(s)
- CCI-000213 - Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
- CCI-000778 - Uniquely identify organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection.
- CCI-001082 - Separate user functionality, including user interface services, from system management functionality.
- CCI-001084 - Isolate security functions from nonsecurity functions.
- CCI-002235 - Prevent non-privileged users from executing privileged functions.
- CCI-002233 - Prevent the organization-defined software from executing at higher privilege levels than users executing the software.
- CCI-002165 - Enforce organization-defined discretionary access control policies over defined subjects and objects.
- CCI-001813 - Enforce access restrictions using organization-defined mechanisms.
- CCI-001774 - Employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs on the system.
- CCI-002696 - Verify correct operation of organization-defined security functions.
- CCI-002699 - Perform verification of the correct operation of organization-defined security functions: when the system is in an organization-defined transitional state; upon command by a user with appropriate privileges; and/or on an organization-defined frequency.
- CCI-003638 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can pass the information to any other subjects or objects.
- CCI-003639 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can grant its privileges to other subjects.
- CCI-003640 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change security attributes on subjects, objects, the system, or the system's components.
- CCI-003641 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can choose the security attributes to be associated with newly created or revised objects.
- CCI-003642 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change the rules governing access control.
Weight
10
Fix Recommendation
Role-Based Access Control hierarchy is to be defined by the AO. Separation of duties must be configured.
Select the gear icon (System Settings) >> Access Management >> LDAP & SAML.
Depending on the multifactor type configured, under LDAP or SAML, locate "User Assignment Settings".
Assign two or more roles as defined by the AO and tie them to an LDAP/SAML user or group.
Check Contents
Role-Based Access Control hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured.
Select the gear icon (System Settings) >> Access Management >> LDAP & SAML.
Depending on the multifactor type configured, under LDAP or SAML, locate "User Assignment Settings".
If only one assigned role exists, this is a finding.
Vulnerability Number
V-276005
Documentable
False
Rule Version
AXOS-00-000025
Severity Override Guidance
Role-Based Access Control hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured.
Select the gear icon (System Settings) >> Access Management >> LDAP & SAML.
Depending on the multifactor type configured, under LDAP or SAML, locate "User Assignment Settings".
If only one assigned role exists, this is a finding.
Check Content Reference
M
Target Key
5710