Ax-OS must have no local accounts for the user interface.
DISA Rule
SV-276012r1156548_rule
Vulnerability Number
V-276012
Group Title
SRG-APP-000150
Rule Version
AXOS-00-000060
Severity
CAT I
CCI(s)
- CCI-000766 - Implement multifactor authentication for network access to non-privileged accounts.
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000016 - Automatically remove or disable temporary and emergency accounts after an organization-defined time-period for each type of account.
- CCI-000017 - Disable accounts when the accounts have been inactive for the organization-defined time-period.
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-004045 - Require users to be individually authenticated before granting access to the shared accounts or resources.
- CCI-004046 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-000185 - For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.
- CCI-000186 - For public key-based authentication, enforce authorized access to the corresponding private key.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-000206 - Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.
- CCI-000804 - Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
- CCI-000884 - Protect nonlocal maintenance sessions by employing organization-defined authenticators that are replay resistant.
- CCI-002145 - Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
- CCI-001953 - Accepts Personal Identity Verification-compliant credentials.
- CCI-001954 - Electronically verifies Personal Identity Verification-compliant credentials.
- CCI-001958 - Authenticate organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection.
- CCI-001967 - Authenticate organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
- CCI-002007 - Prohibit the use of cached authenticators after an organization-defined time period.
- CCI-004068 - For public key-based authentication, implement a local cache of revocation data to support path discovery and validation.
- CCI-002009 - Accept Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-002010 - Electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-004083 - Accept only external credentials that are NIST compliant.
- CCI-004085 - Conform to organization-defined identity management profiles for identity management.
- CCI-001632 - Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by either physically separated communications paths or logically separated communications paths based upon encryption.
- CCI-002470 - Only allow the use of organization-defined certificate authorities for verification of the establishment of protected sessions.
- CCI-003628 - Disable accounts when the accounts are no longer associated to a user.
- CCI-003629 - Disable accounts when the accounts are in violation of organizational policy.
- CCI-003747 - Implement organization-defined mechanisms to authenticate organization-defined remote commands.
- CCI-004047 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that the device meets organization-defined strength of mechanism requirements.
- CCI-004058 - For password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.
- CCI-004059 - For password-based authentication, update the list of passwords on an organization-defined frequency.
- CCI-004060 - For password-based authentication, update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly.
- CCI-004061 - For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
- CCI-004062 - For password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.
- CCI-004063 - For password-based authentication, require immediate selection of a new password upon account recovery.
- CCI-004064 - For password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters.
- CCI-004065 - For password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.
- CCI-004066 - For password-based authentication, enforce organization-defined composition and complexity rules.
- CCI-004192 - Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by logically separated communications paths.
- CCI-004901 - Associate organization-defined privacy attributes with information exchanged between systems.
- CCI-004902 - Associate organization-defined privacy attributes with information exchanged between system components.
Weight
10
Fix Recommendation
Role-Based Access Control hierarchy is to be defined by the AO. Separation of duties must be configured.
Select the gear icon (System Settings) >> User and Role Management >> Users.
After Lightweight Directory Access Protocol (LDAP)/Single Sign-On (SSO) has been configured, remove all local users.
Check Contents
Role-Based Access Control hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured.
Select the gear icon (System Settings) >> User and Role Management >> Users.
In the list of users, verify there are no users with "Internal" listed in the Source column.
If there are any users with "Internal" in the Source column that have not been documented and approved by the AO, this is a finding.
If all users with "Internal" in the Source column are documented and approved by the AO, or if no users with "Internal" in the Source column exist, this is not a finding.
Vulnerability Number
V-276012
Documentable
False
Rule Version
AXOS-00-000060
Severity Override Guidance
Role-Based Access Control hierarchy is to be defined by the authorizing official (AO). Separation of duties must be configured.
Select the gear icon (System Settings) >> User and Role Management >> Users.
In the list of users, verify there are no users with "Internal" listed in the Source column.
If there are any users with "Internal" in the Source column that have not been documented and approved by the AO, this is a finding.
If all users with "Internal" in the Source column are documented and approved by the AO, or if no users with "Internal" in the Source column exist, this is not a finding.
Check Content Reference
M
Target Key
5710