Capacity
CCI-001683
The information system notifies organization-defined personnel or roles for account creation actions.
Choose one
20
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/group
20
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/gshadow
20
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/security/opasswd
20
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/passwd
20
Rule
Severity: Medium
Record Events that Modify User/Group Information - /etc/shadow
1
Rule
Severity: High
The A10 Networks ADC must generate alerts to the administrators and ISSO when accounts are created.
1
Rule
Severity: Medium
AAA Services must be configured to notify the system administrators and ISSO when accounts are created.
1
Rule
Severity: Medium
Compliance Guardian must provide automated mechanisms for supporting account management functions.
1
Rule
Severity: Medium
The Akamai Luna Portal must generate alerts that can be forwarded to the SAs and ISSO when accounts are created.
1
Rule
Severity: Low
The application must notify System Administrators and Information System Security Officers when accounts are created.
1
Rule
Severity: Low
The Central Log Server must notify system administrators and ISSO when accounts are created.
1
Rule
Severity: Medium
The DataPower Gateway must generate alerts that can be forwarded to the administrators and ISSO when accounts are created.
1
Rule
Severity: Medium
The MQ Appliance network device must generate account activity alerts that are forwarded to the administrators and Information System Security Officer (ISSO). Activity includes, creation, removal, modification and re-enablement after being previously disabled.
1
Rule
Severity: Medium
The Mainframe Product must notify system programmers and security administrators when accounts are created.
1
Rule
Severity: Medium
Access to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
1
Rule
Severity: Medium
Riverbed Optimization System (RiOS) must generate alerts that can be forwarded to the administrators and ISSO when local accounts are created.
1
Rule
Severity: High
Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts.
1
Rule
Severity: Low
Splunk Enterprise must notify the System Administrator (SA) and Information System Security Officer (ISSO) when account events are received (creation, deletion, modification, disabling).
2
Rule
Severity: Low
Splunk Enterprise must notify analysts of applicable events for Tier 2 CSSP and JRSS only.
1
Rule
Severity: Medium
Tanium must notify system administrators and ISSO when accounts are created.
2
Rule
Severity: Medium
Tanium must notify system administrator and information system security officer (ISSO) when accounts are created.
2
Rule
Severity: Medium
Tanium must notify SA and ISSO when accounts are created.
1
Rule
Severity: Medium
The Tanium Operating System (TanOS) must notify system administrators and ISSOs when accounts are created.
1
Rule
Severity: Medium
The UEM server must notify system administrators and the Information System Security Officer (ISSO) when accounts are created.
1
Rule
Severity: Medium
The container platform must notify system administrators and ISSO when accounts are created.
1
Rule
Severity: Medium
The operating system must notify system administrators and ISSOs when accounts are created.
1
Rule
Severity: Medium
IBM z/OS system administrator must develop a process notify appropriate personnel when accounts are created.
1
Rule
Severity: Medium
The IBM z/OS System Administrator (SA) must develop a process to notify appropriate personnel when accounts are created.
1
Rule
Severity: Medium
The IBM z/OS System Administrator must develop a process to notify appropriate personnel when accounts are created.
2
Rule
Severity: Medium
OpenShift must generate audit rules to capture account related actions.
2
Rule
Severity: Medium
RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
2
Rule
Severity: Medium
The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
1
Rule
Severity: Low
Splunk Enterprise must notify the System Administrator (SA) and Information System Security Officer (ISSO) when account events are received (creation, deletion, modification, or disabling).
1
Rule
Severity: Medium
The VMM must notify system administrators and ISSOs when accounts are created.
2
Rule
Severity: Medium
The ESXi host must off-load logs via syslog.
4
Rule
Severity: Medium
The vCenter Server must provide an immediate real-time alert to the system administrator (SA) and information system security officer (ISSO), at a minimum, on every Single Sign-On (SSO) account action.
1
Rule
Severity: Medium
The BIG-IP appliance must be configured to generate alerts that can be forwarded to the administrators and Information System Security Officer (ISSO) when accounts are created.
1
Rule
Severity: Low
The application must notify system administrators (SAs) and information system security officers (ISSOs) when accounts are created.
1
Rule
Severity: Medium
The Dragos Platform must notify system administrators and information system security officer (ISSO) of local account activity.
1
Rule
Severity: Medium
MKE must be configured to integrate with an Enterprise Identity Provider.
1
Rule
Severity: Medium
Access to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
1
Rule
Severity: Medium
SLEM 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
1
Rule
Severity: Low
Splunk Enterprise must notify the system administrator (SA) and information system security officer (ISSO) when account events are received (creation, deletion, modification, disabling).
1
Rule
Severity: Low
Splunk Enterprise must notify the system administrator (SA) and information system security officer (ISSO) when account events are received (creation, deletion, modification, or disabling).
1
Rule
Severity: Medium
The Tanium Operating System (TanOS) must notify system administrators (SAs) and information system security officers (ISSOs) when accounts are created.
1
Rule
Severity: Medium
Tanium must notify system administrator (SA) and the information system security officer (ISSO) when accounts are created.
1
Rule
Severity: Medium
The ESXi host must offload logs via syslog.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%