CCI-002007
Prohibit the use of cached authenticators after an organization-defined time period.
The CA API Gateway must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

Citrix License Server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

XenDesktop License Server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The Lifetime Minutes and Renewal Threshold Minutes Login Session Controls must be set to 10 and 0 respectively in Docker Enterprise.
1 rule found Severity: Medium

The HYCU server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The DataPower Gateway must prohibit the use of cached authenticators after an organization-defined time period.
2 rules found Severity: Medium

The IBM Aspera High-Speed Transfer Endpoint must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The IBM Aspera High-Speed Transfer Server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The MQ Appliance WebGUI interface to the messaging server must prohibit the use of cached authenticators after one hour.
1 rule found Severity: Medium

The MQ Appliance SSH interface to the messaging server must prohibit the use of cached authenticators after 600 seconds.
1 rule found Severity: Medium

The WebSphere Application Server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The MQ Appliance network device must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The NSX-T Manager must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The Ubuntu operating system must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day.
2 rules found Severity: Low

2 rules found Severity: Medium

The Cisco ISE must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

1 rule found Severity: Medium

If LDAP authentication is required, AIX must setup LDAP client to refresh user and group caches less than a day.
1 rule found Severity: Medium

The WebSphere Liberty Server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The Juniper EX switch must be configured to prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

1 rule found Severity: Medium

MarkLogic Server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The network device must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The MySQL Database Server 8.0 must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

Redis Enterprise DBMS must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

1 rule found Severity: Medium

If Network Security Services (NSS) is being used by SLEM 5 it must prohibit the use of cached authentications after one day.
1 rule found Severity: Medium

SLEM 5 must configure the Linux Pluggable Authentication Modules (PAM) to prohibit the use of cached offline authentications after one day.
1 rule found Severity: Medium

Apple iOS/iPadOS 18 must implement the management setting: treat AirDrop as an unmanaged destination.
1 rule found Severity: Medium

Apple iOS/iPadOS 18 must implement the management setting: not have any Family Members in Family Sharing.
1 rule found Severity: Low

The application server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Ubuntu 22.04 LTS must be configured such that Pluggable Authentication Module (PAM) prohibits the use of cached authentications after one day.
1 rule found Severity: Low

1 rule found Severity: Medium

The container platform must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Dell OS10 Switch must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

If Network Security Services (NSS) is being used by the SUSE operating system it must prohibit the use of cached authentications after one day.
2 rules found Severity: Medium

The SUSE operating system must configure the Linux Pluggable Authentication Modules (PAM) to prohibit the use of cached offline authentications after one day.
2 rules found Severity: Medium

The UEM server must prohibit the use of cached authenticators after an organization-defined time period.
1 rule found Severity: Medium

The NSX Manager must terminate all network connections associated with a session after five minutes of inactivity.
1 rule found Severity: High
