| Checked | Name | Title |
|---|
| ☐ | SV-204636r1043176_rule | AAA Services must be configured to provide automated account management functions. |
| ☐ | SV-204637r960771_rule | AAA Services must be configured to automatically remove temporary user accounts after 72 hours. |
| ☐ | SV-204638r960771_rule | AAA Services must be configured to automatically remove authorizations for temporary user accounts after 72 hours. |
| ☐ | SV-204639r960774_rule | AAA Services must be configured to automatically disable accounts after a 35-day period of account inactivity. |
| ☐ | SV-204640r960777_rule | AAA Services must be configured to automatically audit account creation. |
| ☐ | SV-204641r960780_rule | AAA Services must be configured to automatically audit account modification. |
| ☐ | SV-204642r960783_rule | AAA Services must be configured to automatically audit account disabling actions. |
| ☐ | SV-204643r960786_rule | AAA Services must be configured to automatically audit account removal actions. |
| ☐ | SV-204644r960840_rule | AAA Services must be configured to automatically lock user accounts after three consecutive invalid logon attempts within a 15-minute time period. |
| ☐ | SV-204645r960879_rule | AAA Services must be configured to audit each authentication and authorization transaction. |
| ☐ | SV-204646r960891_rule | AAA Services configuration audit records must identify what type of events occurred. |
| ☐ | SV-204647r960894_rule | AAA Services configuration audit records must identify when (date and time) the events occurred. |
| ☐ | SV-204648r960897_rule | AAA Services configuration audit records must identify where the events occurred. |
| ☐ | SV-204649r960900_rule | AAA Services configuration audit records must identify the source of the events. |
| ☐ | SV-204650r960903_rule | AAA Services configuration audit records must identify the outcome of the events. |
| ☐ | SV-204651r960906_rule | AAA Services configuration audit records must identify any individual user or process associated with the event. |
| ☐ | SV-204652r960912_rule | AAA Services must be configured to alert the SA and ISSO when any audit processing failure occurs. |
| ☐ | SV-204655r960927_rule | AAA Services must be configured to use internal system clocks to generate time stamps for audit records. |
| ☐ | SV-204656r960963_rule | AAA Services must be configured to disable non-essential modules. |
| ☐ | SV-204657r1043177_rule | AAA Services must be configured to use secure protocols when connecting to directory services. |
| ☐ | SV-204658r1043177_rule | AAA Services must be configured to use protocols that encrypt credentials when authenticating clients, as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-204659r1043177_rule | AAA Services must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-204660r1051115_rule | AAA Services must be configured to uniquely identify and authenticate organizational users. |
| ☐ | SV-204661r960972_rule | AAA Services must be configured to require multifactor authentication using Personal Identity Verification (PIV) credentials for authenticating privileged user accounts. |
| ☐ | SV-204662r960975_rule | AAA Services must be configured to require multifactor authentication using Common Access Card (CAC) Personal Identity Verification (PIV) credentials for authenticating non-privileged user accounts. |
| ☐ | SV-204663r960999_rule | AAA Services used for 802.1x must be configured to uniquely identify network endpoints (supplicants) before the authenticator establishes any connection. |
| ☐ | SV-204664r981554_rule | AAA Services must be configured to enforce a minimum 15-character password length. |
| ☐ | SV-204666r981558_rule | AAA Services must be configured to enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-204667r981561_rule | AAA Services must be configured to enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-204668r981562_rule | AAA Services must be configured to enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-204669r981563_rule | AAA Services must be configured to enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-204670r1043189_rule | AAA Services must be configured to require the change of at least eight of the total number of characters when passwords are changed. |
| ☐ | SV-204671r981567_rule | For password-based authentication, AAA Services must be configured to store passwords using an approved salted key derivation function, preferably using a keyed hash. |
| ☐ | SV-204672r961029_rule | AAA Services must be configured to encrypt transmitted credentials using a FIPS-validated cryptographic module. |
| ☐ | SV-204673r981570_rule | AAA Services must be configured to enforce 24 hours as the minimum password lifetime. |
| ☐ | SV-204674r1043190_rule | AAA Services must be configured to enforce a 60-day maximum password lifetime restriction. |
| ☐ | SV-204675r961038_rule | AAA Services must be configured to only accept certificates issued by a DoD-approved Certificate Authority for PKI-based authentication. |
| ☐ | SV-204676r961038_rule | AAA Services must be configured to not accept certificates that have been revoked for PKI-based authentication. |
| ☐ | SV-204677r961041_rule | AAA Services must be configured to enforce authorized access to the corresponding private key for PKI-based authentication. |
| ☐ | SV-204678r961044_rule | AAA Services must be configured to map the authenticated identity to the user account for PKI-based authentication. |
| ☐ | SV-204679r961128_rule | AAA Services must be configured to protect the confidentiality and integrity of all information at rest. |
| ☐ | SV-204680r971528_rule | AAA Services must be configured to prevent automatically removing emergency accounts. |
| ☐ | SV-204681r971528_rule | AAA Services must be configured to prevent automatically disabling emergency accounts. |
| ☐ | SV-204682r981574_rule | AAA Services must be configured to notify the system administrators (SAs) and information system security officer (ISSO) when accounts are created. |
| ☐ | SV-204683r981577_rule | AAA Services must be configured to notify the system administrators (SAs) and information system security officer (ISSO) when accounts are modified. |
| ☐ | SV-204684r981580_rule | AAA Services must be configured to notify the system administrators (SAs) and information system security officer (ISSO) for account disabling actions. |
| ☐ | SV-204685r981583_rule | AAA Services must be configured to notify the system administrators (SAs) and information system security officer (ISSO) for account removal actions. |
| ☐ | SV-204686r961290_rule | AAA Services must be configured to automatically audit account enabling actions. |
| ☐ | SV-204687r981586_rule | AAA Services must be configured to notify system administrators (SAs) and information system security officer (ISSO) of account enabling actions. |
| ☐ | SV-204689r961368_rule | AAA Services must be configured to maintain locks on user accounts until released by an administrator. |
| ☐ | SV-204690r961395_rule | AAA Services must be configured to send audit records to a centralized audit server. |
| ☐ | SV-204691r961443_rule | AAA Services must be configured to use or map to Coordinated Universal Time (UTC) to record time stamps for audit records. |
| ☐ | SV-204692r961446_rule | AAA Services must be configured with a minimum granularity of one second to record time stamps for audit records. |
| ☐ | SV-204693r961503_rule | AAA Services used for 802.1x must be configured to authenticate network endpoint devices (supplicants) before the authenticator establishes any connection. |
| ☐ | SV-204695r981588_rule | AAA Services must be configured to use at least two NTP servers to synchronize time. |
| ☐ | SV-204696r981589_rule | AAA Services must be configured to authenticate all NTP messages received from NTP servers and peers. |
| ☐ | SV-204697r961863_rule | AAA Services must be configured to use their loopback or OOB management interface address as the source address when originating NTP traffic. |
| ☐ | SV-204698r961863_rule | AAA Services used for 802.1x must be configured to use secure Extensible Authentication Protocol (EAP), such as EAP-TLS, EAP-TTLS, and PEAP. |
| ☐ | SV-204699r961863_rule | AAA Services must not be configured with shared accounts. |
| ☐ | SV-204700r961863_rule | AAA Services used to authenticate privileged users for device management must be configured to connect to the management network. |
| ☐ | SV-204701r961863_rule | AAA Services must be configured to use a unique shared secret for communication (i.e. RADIUS, TACACS+) with clients requesting authentication services. |
| ☐ | SV-204702r961863_rule | AAA Services must be configured to use IP segments separate from production VLAN IP segments. |
| ☐ | SV-204703r961863_rule | AAA Services must be configured to place non-authenticated network access requests in the Unauthorized VLAN or the Guest VLAN with limited access. |
| ☐ | SV-204704r961863_rule | AAA Services must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs. |
| ☐ | SV-263527r982381_rule | AAA Services must be configured to disable accounts when the accounts have expired. |
| ☐ | SV-263528r982383_rule | AAA Services must be configured to disable accounts when the accounts are no longer associated to a user. |
| ☐ | SV-263529r982385_rule | AAA Services must be configured to disable accounts when the accounts are in violation of organizational policy. |
| ☐ | SV-263530r982387_rule | AAA Services must be configured to automatically generate audit records of the enforcement actions. |
| ☐ | SV-263531r982389_rule | AAA Services must be configured to require users to be individually authenticated before granting access to the shared accounts or resources. |
| ☐ | SV-263532r981607_rule | For password-based authentication, AAA Services must be configured to update the list of passwords on an organization-defined frequency. |
| ☐ | SV-263533r981610_rule | For password-based authentication, AAA Services must be configured to update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly. |
| ☐ | SV-263534r981613_rule | For password-based authentication, AAA Services must be configured to verify when users create or update passwords, and that the passwords are not on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a). |
| ☐ | SV-263535r981616_rule | For password-based authentication, AAA Services must be configured to require immediate selection of a new password upon account recovery. |
| ☐ | SV-263536r981619_rule | For password-based authentication, AAA Services must be configured to allow user selection of long passwords and passphrases, including spaces and all printable characters. |
| ☐ | SV-263537r981622_rule | For password-based authentication, AAA Services must be configured to employ automated tools to assist the user in selecting strong password authenticators. |
| ☐ | SV-263538r981625_rule | For public key-based authentication, AAA Services must be configured to implement a local cache of revocation data to support path discovery and validation. |
| ☐ | SV-263539r981628_rule | AAA Services must be configured to include only approved trust anchors in trust stores or certificate stores managed by the organization. |