Capacity
CCI-004046
Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
Choose one
1
Rule
Severity: Medium
Multifactor certificate-based tokens (CAC) must be used when accessing the management interface.
2
Rule
Severity: High
The macOS system must disable password authentication for SSH.
2
Rule
Severity: Medium
The macOS system must enforce smart card authentication.
1
Rule
Severity: Medium
The ALG providing user authentication intermediary services must implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The ALG providing user authentication intermediary services must implement multifactor authentication for remote access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The application server must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The Ubuntu operating system must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
Ubuntu 22.04 LTS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The Central Log Server must be configured to use multifactor authentication for network access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The Cisco ISE must be configured to use an external authentication server to authenticate administrators prior to granting administrative access.
1
Rule
Severity: Medium
The DBMS must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The container platform must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The DNS server implementation must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
Forescout must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.
1
Rule
Severity: Medium
The operating system must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The AIX operating system must use Multi Factor Authentication.
1
Rule
Severity: High
The ICS must be configured to prevent nonprivileged users from executing privileged functions.
1
Rule
Severity: Medium
The Sentry providing mobile device authentication intermediary services must implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: High
The Juniper EX switch must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.
1
Rule
Severity: Medium
The Juniper SRX Services Gateway must be configured to use an authentication server to centrally manage authentication and logon settings for remote and nonlocal access.
1
Rule
Severity: Medium
The Mainframe Product must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The network device must be configured to implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The Oracle Linux operating system must uniquely identify and must authenticate users using multifactor authentication via a graphical user logon.
1
Rule
Severity: Low
OL 8 must have the package required for multifactor authentication installed.
1
Rule
Severity: Medium
OL 8 must implement certificate status checking for multifactor authentication.
1
Rule
Severity: Medium
The Oracle Linux operating system must have the required packages for multifactor authentication installed.
1
Rule
Severity: Medium
The Oracle Linux operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
1
Rule
Severity: Medium
The Oracle Linux operating system must implement certificate status checking for PKI authentication.
1
Rule
Severity: High
The Riverbed NetProfiler must be configured to use an authentication server to authenticate users prior to granting administrative access.
1
Rule
Severity: Medium
RHEL 8 must have the packages required for multifactor authentication installed.
1
Rule
Severity: Medium
RHEL 8 must implement certificate status checking for multifactor authentication.
1
Rule
Severity: Medium
RHEL 9 must have the openssl-pkcs11 package installed.
1
Rule
Severity: Medium
RHEL 9 must enable certificate based smart card authentication.
1
Rule
Severity: Medium
RHEL 9 must implement certificate status checking for multifactor authentication.
1
Rule
Severity: Medium
RHEL 9 must have the pcsc-lite package installed.
1
Rule
Severity: Medium
The pcscd service on RHEL 9 must be active.
1
Rule
Severity: Medium
RHEL 9 must have the opensc package installed.
2
Rule
Severity: Medium
The SUSE operating system must have the packages required for multifactor authentication to be installed.
2
Rule
Severity: Medium
The SUSE operating system must implement certificate status checking for multifactor authentication.
2
Rule
Severity: Medium
The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
1
Rule
Severity: High
Multifactor authentication must be enabled on the Tanium Server for network access with privileged accounts.
1
Rule
Severity: Medium
Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
1
Rule
Severity: High
The TippingPoint SMS must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access and to enforce access restrictions.
1
Rule
Severity: Medium
TOSS must have the packages required for multifactor authentication installed.
1
Rule
Severity: Medium
The VMM must implement multifactor authentication for remote access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The VPN Client must implement multifactor authentication for network access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The web server must implement multifactor authentication for local; network; and/or remote access to privileged accounts; and/or nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
1
Rule
Severity: Medium
The UEM server must be configured to use DOD PKI for multifactor authentication. This requirement is included in SRG-APP-000149.
Patternfly
PatternFly elements
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.
Modules
66%