CCI-000166
Provide irrefutable evidence that an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
The Arista Multilayer Switch must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Low

The DBN-6300 must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Low

A policy set using the built-in role-based access control (RBAC) capabilities in the Universal Control Plane (UCP) component of Docker Enterprise must be configured.
1 rule found Severity: Medium

A policy set using the built-in role-based access control (RBAC) capabilities in the Docker Trusted Registry (DTR) component of Docker Enterprise must be set.
1 rule found Severity: Medium

The HP FlexFabric Switch must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Low

The HYCU VM console and HYCU Web UI must be configured to use an authentication server for authenticating users prior to granting access to protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined requirements.
1 rule found Severity: High

1 rule found Severity: Medium

The MQ Appliance network device must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

MobileIron Sentry, for PKI-based authentication, must be configured to map validated certificates to unique user accounts.
1 rule found Severity: High

SQL Server must protect against an individual using a shared account from falsely denying having performed a particular action.
1 rule found Severity: Medium

Oracle WebLogic must protect against an individual falsely denying having performed a particular action.
1 rule found Severity: Medium

Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2 rules found Severity: Medium

Multi-factor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1 rule found Severity: Medium

The NSX-T Manager must integrate with either VMware Identity Manager (vIDM) or VMware Workspace ONE Access.
1 rule found Severity: High

1 rule found Severity: High

MongoDB must provide audit record generation for DoD-defined auditable events within all DBMS/database components.
2 rules found Severity: Medium

The DBMS must protect against an individual using a group account from falsely denying having performed a particular action.
1 rule found Severity: Low

PostgreSQL must protect against a user falsely repudiating having performed organization-defined actions.
3 rules found Severity: Medium

The EDB Postgres Advanced Server must protect against a user falsely repudiating by ensuring all accounts are individual, unique, and not shared.
1 rule found Severity: Medium

The BIG-IP appliance must be configured to protect against an individual (or process acting on behalf of an individual) falsely denying having performed system configuration changes.
1 rule found Severity: Medium

1 rule found Severity: Medium

IDMS must protect against the use of external request exits that change the userid to a shared id when actions are performed that may be audited.
1 rule found Severity: Low

1 rule found Severity: Low

1 rule found Severity: Low

IDMS must protect against the use web services that do not require a sign on when actions are performed that may be audited.
1 rule found Severity: Low

The Cisco ASA must be configured to protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

4 rules found Severity: Medium

The Cisco ISE must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

The EDB Postgres Advanced Server must protect against a user falsely repudiating having performed organization-defined actions.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to audit the execution of privileged functions such as accounts additions and changes.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to use multifactor authentication (MFA) for interactive logins.
1 rule found Severity: High

1 rule found Severity: Medium

1 rule found Severity: High

Sentry, for PKI-based authentication, must be configured to map validated certificates to unique user accounts.
1 rule found Severity: High

MarkLogic Server must protect against a user falsely repudiating having performed organization-defined actions.
1 rule found Severity: Medium

Azure SQL Database must protect against a user falsely repudiating by ensuring only clearly unique Active Directory user accounts can connect to the database.
1 rule found Severity: Medium

Azure SQL Database must protect against a user falsely repudiating by use of system-versioned tables (Temporal Tables).
1 rule found Severity: Medium

MongoDB must provide audit record generation for DOD-defined auditable events within all DBMS/database components.
1 rule found Severity: Medium

The network device must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

1 rule found Severity: High

The network device, for PKI-based authentication, must be configured to map validated certificates to unique user accounts.
1 rule found Severity: High

The MySQL Database Server 8.0 must protect against a user falsely repudiating having performed organization-defined actions.
1 rule found Severity: Medium

The Riverbed NetProfiler must be configured to automatically generate DOD-required audit records with sufficient information to support incident reporting to a central log server.
1 rule found Severity: High

The Riverbed NetProfiler must be configured to authenticate each administrator prior to authorizing privileges based on roles.
1 rule found Severity: High

Automation Controller must use external log providers that can collect user activity logs in independent, protected repositories to prevent modification or repudiation.
1 rule found Severity: Medium

2 rules found Severity: Medium

Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2 rules found Severity: Medium

The application server must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

The application must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

The Central Log Server must be configured to protect the data sent from hosts and devices from being altered in a way that may prevent the attribution of an action to an individual (or process acting on behalf of an individual).
1 rule found Severity: Medium

The Cisco switch must be configured to protect against an individual falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

The DBMS must protect against a user falsely repudiating having performed organization-defined actions.
1 rule found Severity: Medium

The Dell OS10 Switch must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by nonrepudiation.
1 rule found Severity: Medium

The Dell OS10 Switch, for PKI-based authentication, must be configured to map validated certificates to unique user accounts.
1 rule found Severity: High

1 rule found Severity: Medium

AOS must be configured to use DOD public key infrastructure (PKI) as multifactor authentication (MFA) for interactive logins.
1 rule found Severity: High

The HYCU virtual appliance must be configured to use DOD-approved online certificate status protocol (OCSP) responders or certificate revocation lists (CRLs) to validate certificates used for PKI-based authentication.
1 rule found Severity: High

The Juniper router must be configured to protect against an individual falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

The Mainframe Product must protect against an individual (or process acting on behalf of an individual) falsely denying having performed actions defined in the site security plan to be covered by non-repudiation.
1 rule found Severity: Medium

MariaDB must protect against a user falsely repudiating having performed organization-defined actions.
1 rule found Severity: Medium

SQL Server must protect against a user falsely repudiating by ensuring only clearly unique Active Directory user accounts can connect to the database.
1 rule found Severity: Medium

SQL Server must protect against a user falsely repudiating by use of system-versioned tables (Temporal Tables).
1 rule found Severity: Low

SQL Server must protect against a user falsely repudiating by ensuring databases are not in a trust relationship.
1 rule found Severity: Medium

SQL Server must protect against a user falsely repudiating by ensuring all accounts are individual, unique, and not shared.
1 rule found Severity: Medium

SQL Server must protect against a user falsely repudiating by ensuring the NT AUTHORITY SYSTEM account is not used for administration.
1 rule found Severity: Medium

SQL Server must protect against a user falsely repudiating by ensuring only clearly unique Active Directory user accounts can connect to the instance.
1 rule found Severity: Medium

The DBMS must protect against an individual who uses a shared account falsely denying having performed a particular action.
1 rule found Severity: Low

The operating system must protect against an individual falsely denying having performed a particular action. In order to do so the system must be configured to send audit records to a remote audit server.
2 rules found Severity: Low

The UEM server must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
1 rule found Severity: Medium

The NSX Manager must be configured to integrate with an identity provider that supports multifactor authentication (MFA).
1 rule found Severity: High

The vCenter ESX Agent Manager service must produce log records containing sufficient information regarding event details.
2 rules found Severity: Medium

The vCenter Lookup service must produce log records containing sufficient information regarding event details.
2 rules found Severity: Medium

The vCenter Perfcharts service must produce log records containing sufficient information regarding event details.
2 rules found Severity: Medium

The vCenter STS service must produce log records containing sufficient information regarding event details.
2 rules found Severity: Medium

The vCenter UI service must produce log records containing sufficient information regarding event details.
2 rules found Severity: Medium
