Fly Server must have no local accounts for the user interface.
DISA Rule
SV-283938r1223357_rule
Vulnerability Number
V-283938
Group Title
SRG-APP-000150
Rule Version
FLYS-00-000110
Severity
CAT I
CCI(s)
- CCI-000766 - Implement multifactor authentication for network access to non-privileged accounts.
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000016 - Automatically remove or disable temporary and emergency accounts after an organization-defined time-period for each type of account.
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-004045 - Require users to be individually authenticated before granting access to the shared accounts or resources.
- CCI-004046 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-000185 - For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.
- CCI-000186 - For public key-based authentication, enforce authorized access to the corresponding private key.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-000206 - Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unauthorized individuals.
- CCI-000804 - Uniquely identify and authenticate non-organizational users or processes acting on behalf of non-organizational users.
- CCI-000884 - Protect nonlocal maintenance sessions by employing organization-defined authenticators that are replay resistant.
- CCI-002145 - Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
- CCI-001953 - Accepts Personal Identity Verification-compliant credentials.
- CCI-001954 - Electronically verifies Personal Identity Verification-compliant credentials.
- CCI-001958 - Authenticate organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection.
- CCI-001967 - Authenticate organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
- CCI-002007 - Prohibit the use of cached authenticators after an organization-defined time period.
- CCI-004068 - For public key-based authentication, implement a local cache of revocation data to support path discovery and validation.
- CCI-002009 - Accept Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-002010 - Electronically verify Personal Identity Verification-compliant credentials from other federal agencies.
- CCI-004083 - Accept only external credentials that are NIST compliant.
- CCI-004085 - Conform to organization-defined identity management profiles for identity management.
- CCI-001632 - Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by either physically separated communications paths or logically separated communications paths based upon encryption.
- CCI-002470 - Only allow the use of organization-defined certificate authorities for verification of the establishment of protected sessions.
- CCI-003628 - Disable accounts when the accounts are no longer associated to a user.
- CCI-003629 - Disable accounts when the accounts are in violation of organizational policy.
- CCI-003747 - Implement organization-defined mechanisms to authenticate organization-defined remote commands.
- CCI-004047 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that the device meets organization-defined strength of mechanism requirements.
- CCI-004058 - For password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.
- CCI-004059 - For password-based authentication, update the list of passwords on an organization-defined frequency.
- CCI-004060 - For password-based authentication, update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly.
- CCI-004061 - For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
- CCI-004062 - For password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.
- CCI-004063 - For password-based authentication, require immediate selection of a new password upon account recovery.
- CCI-004064 - For password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters.
- CCI-004065 - For password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.
- CCI-004066 - For password-based authentication, enforce organization-defined composition and complexity rules.
- CCI-004192 - Protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by logically separated communications paths.
- CCI-004901 - Associate organization-defined privacy attributes with information exchanged between systems.
- CCI-004902 - Associate organization-defined privacy attributes with information exchanged between system components.
Weight
10
Fix Recommendation
Once Active Directory is configured in FLYS-00-000055, remove all local users:
- On the Management >> Account Manager tab, remove all local users.
Check Contents
Once Active Directory is configured in FLYS-00-000055, all local users must be removed.
Check the Fly Server User settings:
- On the Management >> Account Manager tab, view the list of users.
- User accounts tied to an Active Directory domain will be defined as [domainname]\[username].
If any of the users listed are not tied to Active Directory, this is a finding.
Vulnerability Number
V-283938
Documentable
False
Rule Version
FLYS-00-000110
Severity Override Guidance
Once Active Directory is configured in FLYS-00-000055, all local users must be removed.
Check the Fly Server User settings:
- On the Management >> Account Manager tab, view the list of users.
- User accounts tied to an Active Directory domain will be defined as [domainname]\[username].
If any of the users listed are not tied to Active Directory, this is a finding.
Check Content Reference
M
Target Key
5747