Capacity
CCI-001953
Accepts Personal Identity Verification-compliant credentials.
Choose one
13
Rule
Severity: Medium
Install the opensc Package For Multifactor Authentication
14
Rule
Severity: Medium
Install Smart Card Packages For Multifactor Authentication
8
Rule
Severity: Medium
Configure Smart Card Certificate Status Checking
8
Rule
Severity: Medium
Configure PAM in SSSD Services
3
Rule
Severity: Medium
Enable Smart Card Logins in PAM
1
Rule
Severity: High
Compliance Guardian must use multifactor authentication for network access to privileged accounts.
2
Rule
Severity: High
The application server must accept Personal Identity Verification (PIV) credentials to access the management interface.
2
Rule
Severity: Medium
The application must accept Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The Central Log Server must be configured to accept the DoD CAC credential to support identity management and personal authentication.
1
Rule
Severity: Medium
Citrix Receiver must accept Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
Citrix StoreFront server must accept Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
LDAP integration in Docker Enterprise must be configured.
1
Rule
Severity: Medium
SAML integration must be enabled in Docker Enterprise.
1
Rule
Severity: Medium
The WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.
1
Rule
Severity: Medium
WebGUI access to the MQ Appliance network device must accept Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Low
The ISEC7 EMM Suite must accept Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The Mainframe Product must accept Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
Exchange Outlook Anywhere (OA) clients must use NTLM authentication to access email.
1
Rule
Severity: Medium
Nutanix AOS must accept Personal Identity Verification (PIV) credentials to access the management interface.
2
Rule
Severity: Medium
Prisma Cloud Compute local accounts must enforce strong password requirements.
2
Rule
Severity: Medium
Prisma Cloud Compute must be configured to require local user accounts to use x.509 multifactor authentication.
1
Rule
Severity: High
Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts.
1
Rule
Severity: Medium
Splunk Enterprise must use an SSO proxy service, F5 device, or SAML implementation to accept the DoD CAC or other smart card credential for identity management, personal authentication, and multifactor authentication.
2
Rule
Severity: Medium
Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2
Rule
Severity: Medium
The Tanium application must accept Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
Multi-factor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2
Rule
Severity: Medium
The VPN Gateway must accept the Common Access Card (CAC) credential.
2
Rule
Severity: Medium
Multifactor certificate-based tokens (CAC) must be used when accessing the management interface.
1
Rule
Severity: Medium
The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.
3
Rule
Severity: Medium
The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DOD PKI-established certificate authorities for verification of the establishment of protected sessions.
3
Rule
Severity: Medium
The macOS system must enforce smart card authentication.
3
Rule
Severity: Medium
The macOS system must allow smart card authentication.
3
Rule
Severity: Medium
The Ubuntu operating system must accept Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The Cisco VPN remote access server must be configured to accept Common Access Card (CAC) credential credentials.
2
Rule
Severity: Medium
The container platform must be configured to use multi-factor authentication for user authentication.
2
Rule
Severity: Medium
The operating system must accept Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The AIX operating system must accept and verify Personal Identity Verification (PIV) credentials.
3
Rule
Severity: Medium
Exchange Outlook Anywhere clients must use NTLM authentication to access email.
2
Rule
Severity: Medium
The Oracle Linux operating system must have the required packages for multifactor authentication installed.
2
Rule
Severity: Medium
The Oracle Linux operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
2
Rule
Severity: Medium
The Oracle Linux operating system must implement certificate status checking for PKI authentication.
2
Rule
Severity: Medium
OL 8 must accept Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The Palo Alto Networks security platform must accept and verify Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
Automation Controller must be configured to use an enterprise user management system.
2
Rule
Severity: High
OpenShift must use FIPS validated LDAP or OpenIDConnect.
2
Rule
Severity: Medium
RHEL 8 must accept Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
The Red Hat Enterprise Linux operating system must uniquely identify and must authenticate users using multifactor authentication via a graphical user logon.
1
Rule
Severity: Medium
The Red Hat Enterprise Linux operating system must have the required packages for multifactor authentication installed.
1
Rule
Severity: Medium
The Red Hat Enterprise Linux operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
1
Rule
Severity: Medium
The Red Hat Enterprise Linux operating system must implement certificate status checking for PKI authentication.
2
Rule
Severity: Medium
RHEL 9 must have the openssl-pkcs11 package installed.
4
Rule
Severity: Medium
The SUSE operating system must have the packages required for multifactor authentication to be installed.
4
Rule
Severity: Medium
The SUSE operating system must implement certificate status checking for multifactor authentication.
4
Rule
Severity: Medium
The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
2
Rule
Severity: Medium
RHEL 9 must have the opensc package installed.
1
Rule
Severity: High
Splunk Enterprise must accept the DoD CAC or other PKI credential for identity management and personal authentication.
2
Rule
Severity: Medium
The VMM must accept Personal Identity Verification (PIV) credentials.
4
Rule
Severity: Medium
The vCenter Server must require multifactor authentication.
1
Rule
Severity: Medium
Ubuntu 22.04 LTS must accept personal identity verification (PIV) credentials.
1
Rule
Severity: Medium
Dragos Platform must accept the DOD CAC or other PKI credential for identity management and personal authentication.
1
Rule
Severity: Low
The ISEC7 SPHERE must accept Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
MKE must be configured to integrate with an Enterprise Identity Provider.
1
Rule
Severity: Medium
SLEM 5 must have the packages required for multifactor authentication to be installed.
1
Rule
Severity: Medium
SLEM 5 must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
1
Rule
Severity: Medium
SLEM 5 must implement certificate status checking for multifactor authentication.
1
Rule
Severity: Medium
Splunk Enterprise must use an SSO proxy service, F5 device, or SAML implementation to accept the DOD common access card (CAC) or other smart card credential for identity management, personal authentication, and multifactor authentication.
1
Rule
Severity: High
Splunk Enterprise must accept the DOD CAC or other PKI credential for identity management and personal authentication.
1
Rule
Severity: Medium
Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1
Rule
Severity: Medium
TOSS must accept Personal Identity Verification (PIV) credentials.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%