STIGQter STIGQter: STIG Summary: Authentication, Authorization, and Accounting Services (AAA) Security Requirements Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

AAA Services must be configured to provide automated account management functions.

DISA Rule

SV-95529r1_rule

Vulnerability Number

V-80819

Group Title

SRG-APP-000023-AAA-000030

Rule Version

SRG-APP-000023-AAA-000030

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure AAA Services to provide automated account management functions. Automated functions include disabling accounts after specified periods of inactivity, locking accounts after a specified number of incorrect logon attempts, etc. Where possible, automated functions must be performed on users and devices globally rather than by each individual account.

Check Contents

If AAA Services rely on directory services for user account management, this is not applicable and the connected directory services must perform this function.

Verify AAA Services are configured to provide automated account management functions. Automated functions include disabling accounts after specified periods of inactivity, locking accounts after a specified number of incorrect logon attempts, etc. Where possible, automated functions must be performed on users and devices globally rather than by each individual account.

If AAA Services do not provide automated account management functions, this is a finding.

Vulnerability Number

V-80819

Documentable

False

Rule Version

SRG-APP-000023-AAA-000030

Severity Override Guidance

If AAA Services rely on directory services for user account management, this is not applicable and the connected directory services must perform this function.

Verify AAA Services are configured to provide automated account management functions. Automated functions include disabling accounts after specified periods of inactivity, locking accounts after a specified number of incorrect logon attempts, etc. Where possible, automated functions must be performed on users and devices globally rather than by each individual account.

If AAA Services do not provide automated account management functions, this is a finding.

Check Content Reference

M

Target Key

3357

Comments