Fly Server must use an approved DoW enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate organizational users.
DISA Rule
SV-283928r1223356_rule
Vulnerability Number
V-283928
Group Title
SRG-APP-000155
Rule Version
FLYS-00-000055
Severity
CAT I
CCI(s)
- CCI-004046 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-000766 - Implement multifactor authentication for network access to non-privileged accounts.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-004066 - For password-based authentication, enforce organization-defined composition and complexity rules.
- CCI-002145 - Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.
- CCI-002205 - Uniquely identify and authenticate source by organization, system, application, service, and/or individual for information transfer.
- CCI-000366 - Implement the security configuration settings.
- CCI-001953 - Accepts Personal Identity Verification-compliant credentials.
- CCI-001954 - Electronically verifies Personal Identity Verification-compliant credentials.
- CCI-002009 - Accept Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-002010 - Electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-004083 - Accept only external credentials that are NIST compliant.
- CCI-004085 - Conform to organization-defined identity management profiles for identity management.
- CCI-003747 - Implement organization-defined mechanisms to authenticate organization-defined remote commands.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-003628 - Disable accounts when the accounts are no longer associated to a user.
- CCI-003629 - Disable accounts when the accounts are in violation of organizational policy.
- CCI-004047 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that the device meets organization-defined strength of mechanism requirements.
- CCI-004058 - For password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.
- CCI-004068 - For public key-based authentication, implement a local cache of revocation data to support path discovery and validation.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-004045 - Require users to be individually authenticated before granting access to the shared accounts or resources.
- CCI-001083 - Prevent the presentation of system management functionality at an interface for non-privileged users.
- CCI-000185 - For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.
- CCI-000186 - For public key-based authentication, enforce authorized access to the corresponding private key.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-001967 - Authenticate organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
- CCI-002007 - Prohibit the use of cached authenticators after an organization-defined time period.
Weight
10
Fix Recommendation
Configure the Fly Server Account Manager setting to ensure AD Integration or AAD Integration is enabled:
- Log on to Fly Server with an admin account.
- On the Management >> Account Manager page, click "Authentication Manager".
- Navigate to AD Integration or AAD Integration.
- Set the Action of AD Integration or AAD Integration to "Enable".
- Add an AD domain after AD integration is enabled.
- Save the setting.
Add AD user/group or AAD user/group to Account Manager; realize automated mechanisms through AD or AAD account management functions.
Check Contents
Fly Server must be integrated with Active Directory (AD) and Azure AD (AAD) for automated account management.
Check the Fly Server Account Manager setting to verify AD Integration or AAD Integration is enabled:
- Log on to Fly Server with an admin account.
- On the Management >> Account Manager page, click "Authentication Manager".
- Navigate to AD Integration or AAD Integration.
- Verify the AD Integration or AAD Integration option is enabled.
If the AD Integration or AAD Integration option is not enabled, this is a finding.
Vulnerability Number
V-283928
Documentable
False
Rule Version
FLYS-00-000055
Severity Override Guidance
Fly Server must be integrated with Active Directory (AD) and Azure AD (AAD) for automated account management.
Check the Fly Server Account Manager setting to verify AD Integration or AAD Integration is enabled:
- Log on to Fly Server with an admin account.
- On the Management >> Account Manager page, click "Authentication Manager".
- Navigate to AD Integration or AAD Integration.
- Verify the AD Integration or AAD Integration option is enabled.
If the AD Integration or AAD Integration option is not enabled, this is a finding.
Check Content Reference
M
Target Key
5747