Capacity
CCI-001954
Electronically verifies Personal Identity Verification-compliant credentials.
Choose one
10
Rule
Severity: Medium
Enable the GNOME3 Login Smartcard Authentication
13
Rule
Severity: Medium
Install the opensc Package For Multifactor Authentication
12
Rule
Severity: Medium
Install the pcsc-lite package
14
Rule
Severity: Medium
Install Smart Card Packages For Multifactor Authentication
14
Rule
Severity: Medium
Enable the pcscd Service
8
Rule
Severity: Medium
Configure Smart Card Certificate Status Checking
8
Rule
Severity: Medium
Configure PAM in SSSD Services
15
Rule
Severity: Medium
Enable Smartcards in SSSD
7
Rule
Severity: Medium
Certificate status checking in SSSD
3
Rule
Severity: Medium
Enable Smart Card Logins in PAM
1
Rule
Severity: High
Compliance Guardian must use multifactor authentication for network access to privileged accounts.
2
Rule
Severity: High
The application server must electronically verify Personal Identity Verification (PIV) credentials for access to the management interface.
2
Rule
Severity: Medium
The application must electronically verify Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The Central Log Server must be configured to electronically verify the DoD CAC credential.
1
Rule
Severity: Medium
Citrix Receiver must accept Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
Citrix StoreFront server must accept Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
LDAP integration in Docker Enterprise must be configured.
1
Rule
Severity: Medium
SAML integration must be enabled in Docker Enterprise.
1
Rule
Severity: Medium
The WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.
1
Rule
Severity: Medium
WebGUI access to the MQ Appliance network device must electronically verify Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The Mainframe Product must electronically verify Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
Nutanix AOS must accept Personal Identity Verification (PIV) credentials to access the management interface.
1
Rule
Severity: High
Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts.
2
Rule
Severity: Medium
Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2
Rule
Severity: Medium
The Tanium application must electronically verify Personal Identity Verification (PIV) credentials.
1
Rule
Severity: Medium
Multi-factor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
2
Rule
Severity: Medium
The VPN Gateway must electronically verify the Common Access Card (CAC) credential.
2
Rule
Severity: Medium
Multifactor certificate-based tokens (CAC) must be used when accessing the management interface.
1
Rule
Severity: Medium
The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.
3
Rule
Severity: Medium
The macOS system must accept and verify Personal Identity Verification (PIV) credentials, implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network, and only allow the use of DOD PKI-established certificate authorities for verification of the establishment of protected sessions.
3
Rule
Severity: Medium
The macOS system must set smart card certificate trust to moderate.
1
Rule
Severity: Medium
The Ubuntu operating system must implement smart card logins for multifactor authentication for access to accounts.
1
Rule
Severity: Medium
The Ubuntu operating system must implement certificate status checking for multifactor authentication.
2
Rule
Severity: Medium
The Ubuntu operating system must electronically verify Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The operating system must electronically verify Personal Identity Verification (PIV) credentials.
2
Rule
Severity: Medium
The AIX operating system must accept and verify Personal Identity Verification (PIV) credentials.
2
Rule
Severity: High
The ICS must be configured to use multifactor authentication (e.g., DOD PKI) for network access to nonprivileged accounts.
1
Rule
Severity: Medium
Prevent ignoring certificate errors option must be enabled.
2
Rule
Severity: Medium
The Oracle Linux operating system must have the required packages for multifactor authentication installed.
2
Rule
Severity: Medium
The Oracle Linux operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
2
Rule
Severity: Medium
The Oracle Linux operating system must implement certificate status checking for PKI authentication.
2
Rule
Severity: Medium
OL 8 must implement certificate status checking for multifactor authentication.
2
Rule
Severity: Medium
Automation Controller must be configured to use an enterprise user management system.
1
Rule
Severity: Medium
The Red Hat Enterprise Linux operating system must uniquely identify and must authenticate users using multifactor authentication via a graphical user logon.
1
Rule
Severity: Medium
The Red Hat Enterprise Linux operating system must have the required packages for multifactor authentication installed.
1
Rule
Severity: Medium
The Red Hat Enterprise Linux operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
1
Rule
Severity: Medium
The Red Hat Enterprise Linux operating system must implement certificate status checking for PKI authentication.
2
Rule
Severity: Medium
RHEL 9 must have the openssl-pkcs11 package installed.
4
Rule
Severity: Medium
The SUSE operating system must have the packages required for multifactor authentication to be installed.
4
Rule
Severity: Medium
The SUSE operating system must implement certificate status checking for multifactor authentication.
4
Rule
Severity: Medium
The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
2
Rule
Severity: Medium
RHEL 9 must implement certificate status checking for multifactor authentication.
2
Rule
Severity: Medium
The VMM must electronically verify Personal Identity Verification (PIV) credentials.
4
Rule
Severity: Medium
The vCenter Server must enable revocation checking for certificate-based authentication.
1
Rule
Severity: Medium
Ubuntu 22.04 LTS must electronically verify personal identity verification (PIV) credentials.
1
Rule
Severity: Medium
The cloud service offering (CSO) must be configured to use DOD public key infrastructure (PKI) to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
1
Rule
Severity: Medium
Dragos Platform must accept the DOD CAC or other PKI credential for identity management and personal authentication.
1
Rule
Severity: Medium
SLEM 5 must have the packages required for multifactor authentication to be installed.
1
Rule
Severity: Medium
SLEM 5 must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
1
Rule
Severity: Medium
SLEM 5 must implement certificate status checking for multifactor authentication.
1
Rule
Severity: Medium
Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%