CCI-002038
The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication.
7 rules found Severity: Medium

7 rules found Severity: Medium

7 rules found Severity: Medium

The CA API Gateway providing user authentication intermediary services must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

The Lifetime Minutes and Renewal Threshold Minutes Login Session Controls must be set to 10 and 0 respectively in Docker Enterprise.
1 rule found Severity: Medium

CounterACT, when providing user authentication intermediary services, must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

The DataPower Gateway must require users to re-authenticate when privilege escalation or role changes occur.
1 rule found Severity: Medium

1 rule found Severity: Medium

Symantec ProxySG providing user authentication intermediary services must require users to reauthenticate every 900 seconds when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

The Ubuntu operating system must require users to re-authenticate for privilege escalation and changing roles.
1 rule found Severity: Medium

MongoDB must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
2 rules found Severity: Medium

PostgreSQL must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
3 rules found Severity: Medium

The Red Hat Enterprise Linux operating system must be configured so that users must provide a password for privilege escalation.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must be configured so that users must re-authenticate for privilege escalation.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must require re-authentication when using the "sudo" command.
1 rule found Severity: Medium

The Red Hat Enterprise Linux operating system must not be configured to bypass password requirements for privilege escalation.
1 rule found Severity: Medium

The EDB Postgres Advanced Server must require users to re-authenticate when organization-defined circumstances or situations require re-authentication.
1 rule found Severity: Medium

The BIG-IP APM module must require users to reauthenticate when the user's role or information authorizations are changed.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to set a "Maximum Session Timeout" value of 8 hours or less.
1 rule found Severity: Medium

The BIG-IP Core implementation must require users to reauthenticate when the user's role, the information authorizations, and/or the maximum session timeout is exceeded for the virtual server(s).
1 rule found Severity: Medium

1 rule found Severity: Medium

The macOS system must require users to reauthenticate for privilege escalation when using the "sudo" command.
2 rules found Severity: Medium

The Ubuntu operating system must require users to reauthenticate for privilege escalation or when changing roles.
1 rule found Severity: Medium

The Cisco ASA VPN gateway must be configured to renegotiate the IPsec Security Association after eight hours or less.
1 rule found Severity: Medium

The Cisco ASA VPN gateway must be configured to renegotiate the IKE security association after 24 hours or less.
1 rule found Severity: Medium

The F5 BIG-IP appliance providing user authentication intermediary services must require users to reauthenticate when the user's role or information authorizations is changed.
1 rule found Severity: Medium

The EDB Postgres Advanced Server must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to set a Maximum Session Timeout value of eight hours or less.
1 rule found Severity: Medium

The F5 BIG-IP appliance IPsec VPN Gateway must renegotiate the IPsec Phase 1 security association after eight hours or less.
1 rule found Severity: Medium

The F5 BIG-IP appliance IPsec VPN must renegotiate the IKE Phase 2 security association after eight hours or less.
1 rule found Severity: Medium

SSMC must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

4 rules found Severity: Medium

4 rules found Severity: Medium

5 rules found Severity: Medium

5 rules found Severity: Medium

5 rules found Severity: Medium

4 rules found Severity: Medium

5 rules found Severity: Medium

1 rule found Severity: Medium

The Oracle Linux operating system must be configured so that users must provide a password for privilege escalation.
1 rule found Severity: Medium

The Oracle Linux operating system must be configured so users must re-authenticate for privilege escalation.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Oracle Linux operating system must not be configured to bypass password requirements for privilege escalation.
1 rule found Severity: Medium

The MySQL Database Server 8.0 must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

Redis Enterprise DBMS must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Low

1 rule found Severity: Medium

The application server must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

The ALG providing user authentication intermediary services must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

The application must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

The application must require devices to reauthenticate when organization-defined circumstances or situations requiring reauthentication.
1 rule found Severity: Medium

Ubuntu 22.04 LTS must require users to reauthenticate for privilege escalation or when changing roles.
1 rule found Severity: Medium

The Central Log Server must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Low

The container platform must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

The DBMS must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

AOS, when used as a VPN Gateway, must renegotiate the security association after 24 hours or less or as defined by the organization.
1 rule found Severity: Medium

MariaDB must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
1 rule found Severity: Medium

1 rule found Severity: Medium

Windows Server 2019 Remote Desktop Services must always prompt a client for passwords upon connection.
1 rule found Severity: Medium

1 rule found Severity: Medium

Windows Server 2019 User Account Control approval mode for the built-in Administrator must be enabled.
1 rule found Severity: Medium

Windows Server 2019 User Account Control must automatically deny standard user requests for elevation.
1 rule found Severity: Medium

Windows Server 2019 User Account Control must run all administrators in Admin Approval Mode, enabling UAC.
1 rule found Severity: Medium

1 rule found Severity: Medium

Windows Server 2022 Remote Desktop Services must always prompt a client for passwords upon connection.
1 rule found Severity: Medium

1 rule found Severity: Medium

Windows Server 2022 User Account Control (UAC) approval mode for the built-in Administrator must be enabled.
1 rule found Severity: Medium

Windows Server 2022 User Account Control (UAC) must automatically deny standard user requests for elevation.
1 rule found Severity: Medium

Windows Server 2022 User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

OpenShift must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity.
1 rule found Severity: Medium

The OL 8 operating system must not be configured to bypass password requirements for privilege escalation.
1 rule found Severity: Medium

1 rule found Severity: Medium

The RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges.
2 rules found Severity: High

1 rule found Severity: Medium

The SUSE operating system must not be configured to bypass password requirements for privilege escalation.
2 rules found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium
