Capacity
CCI-002142
The information system terminates shared/group account credentials when members leave the group.
Choose one
1
Rule
Severity: Medium
When anyone who has access to the emergency administration account no longer requires access to it or leaves the organization, the password for the emergency administration account must be changed.
2
Rule
Severity: Medium
Shared/group account credentials must be terminated when members leave the group.
4
Rule
Severity: Medium
The network device must terminate shared/group account credentials when members leave the group.
2
Rule
Severity: Medium
Forescout must terminate the account of last resort password when members with access to the password leave the group.
1
Rule
Severity: Medium
The HYCU server must terminate shared/group account credentials when members leave the group.
1
Rule
Severity: Medium
The MQ Appliance network device must terminate shared/group account credentials when members leave the group.
1
Rule
Severity: Medium
The Mainframe Product must terminate shared/group account credentials when members leave the group.
1
Rule
Severity: Medium
Members of the SCOM Administrators Group must be reviewed to ensure access is still required.
1
Rule
Severity: Medium
Access to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
1
Rule
Severity: Medium
Riverbed Optimization System (RiOS) must terminate local shared/group account credentials, such as the Admin account is used, when members who know the account password leave the group.
1
Rule
Severity: Medium
Riverbed Optimization System (RiOS) must disable the local Shark and Monitor accounts so they cannot be used as shared accounts by users.
1
Rule
Severity: Medium
The Tanium Server must be configured with a connector to sync to Microsoft Active Directory for account management functions, must isolate security functions from non-security functions, and must terminate shared/group account credentials when members leave the group.
5
Rule
Severity: Medium
The Tanium Application Server must be configured with a connector to sync to Microsoft Active Directory for account management functions.
4
Rule
Severity: Medium
The Tanium cryptographic signing capabilities must be enabled on the Tanium Server.
2
Rule
Severity: Medium
The password for the local account of last resort and the device password (if configured) must be changed when members who had access to the password leave the role and are no longer authorized access.
2
Rule
Severity: Medium
The Cisco ISE must change the password for the local CLI and web-based account when members who have access to the password leave the role and are no longer authorized access.
1
Rule
Severity: Medium
The container platform must terminate shared/group account credentials when members leave the group.
2
Rule
Severity: Medium
The Juniper EX switch must change credentials for account of last resort when administrators who know the credential leave the organization.
2
Rule
Severity: High
OpenShift must use FIPS validated LDAP or OpenIDConnect.
1
Rule
Severity: Medium
Dragos Platform must use an Identity Provider (IDP) for authentication and authorization processes.
1
Rule
Severity: Medium
The F5 BIG-IP appliance must terminate shared/group account credentials when members leave the group.
1
Rule
Severity: Medium
MKE must be configured to integrate with an Enterprise Identity Provider.
1
Rule
Severity: Medium
Access to Prisma Cloud Compute must be managed based on user need and least privileged using external identity providers for authentication and grouping to role-based assignments when possible.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%