CCI-001686
The information system notifies organization-defined personnel or roles for account removal actions.
6 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Akamai Luna Portal must generate alerts that can be forwarded to the SAs and ISSO when accounts are removed.
1 rule found Severity: Medium

The DataPower Gateway must generate alerts that can be forwarded to the administrators and ISSO when accounts are removed.
1 rule found Severity: Medium

The MQ Appliance network device must generate account activity alerts that are forwarded to the administrators and Information System Security Officer (ISSO). Activity includes, creation, removal, modification and re-enablement after being previously disabled.
1 rule found Severity: Medium

Riverbed Optimization System (RiOS) must generate alerts that can be forwarded to the administrators and ISSO when accounts are removed.
1 rule found Severity: Low

Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts.
1 rule found Severity: High

Tanium must notify System Administrators and Information System Security Officers for account removal actions.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Tanium Operating System (TanOS) must notify system administrators and ISSOs when accounts are removed.
1 rule found Severity: Medium

The BIG-IP appliance must be configured to generate alerts that can be forwarded to the administrators and Information System Security Officer (ISSO) when accounts are removed.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

SLEM 5 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
1 rule found Severity: Medium

Splunk Enterprise must notify the system administrator (SA) and information system security officer (ISSO) when account events are received (creation, deletion, modification, disabling).
1 rule found Severity: Low

1 rule found Severity: Low

Splunk Enterprise must notify the system administrator (SA) and information system security officer (ISSO) when account events are received (creation, deletion, modification, or disabling).
1 rule found Severity: Low

The Tanium Operating System (TanOS) must notify system administrators (SAs) and information system security officers (ISSOs) when accounts are removed.
1 rule found Severity: Medium

Tanium must notify system administrators (SAs) and the information system security officer (ISSO) for account removal actions.
1 rule found Severity: Medium

Tanium must notify system administrators and the information system security officer (ISSO) for account removal actions.
1 rule found Severity: Medium

The application must notify system administrators (SAs) and information system security officers (ISSOs) of account removal actions.
1 rule found Severity: Low

The Dragos Platform must notify system administrators and information system security officer (ISSO) of local account activity.
1 rule found Severity: Medium

In the event that communications with the events server is lost, the Juniper SRX Services Gateway must continue to queue log records locally.
1 rule found Severity: Medium

Access to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
1 rule found Severity: Medium

1 rule found Severity: Medium

RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
1 rule found Severity: Medium

The SUSE operating system must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.
1 rule found Severity: Medium
