Skip to content

Authentication, Authorization, and Accounting Services (AAA) Security Requirements Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000029-AAA-000120

    <GroupDescription></GroupDescription>
    Group
  • AAA Services must be configured to send audit records to a centralized audit server.

    &lt;VulnDiscussion&gt;Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Off-loading is a common...
    Rule Medium Severity
  • AAA Services must be configured to automatically audit account removal actions.

    &lt;VulnDiscussion&gt;When application accounts are removed, user accessibility is affected. Once an attacker establishes access to an application,...
    Rule Medium Severity
  • SRG-APP-000291-AAA-000130

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000108-AAA-000290

    <GroupDescription></GroupDescription>
    Group
  • SRG-APP-000142-AAA-000020

    <GroupDescription></GroupDescription>
    Group
  • AAA Services must be configured to use protocols that encrypt credentials when authenticating clients, as defined in the PPSM CAL and vulnerability assessments.

    &lt;VulnDiscussion&gt;Authentication protection of the client credentials (specifically the password or shared secret) prevents unauthorized access...
    Rule High Severity
  • SRG-APP-000023-AAA-000030

    <GroupDescription></GroupDescription>
    Group
  • AAA Services must be configured to provide automated account management functions.

    &lt;VulnDiscussion&gt;Enterprise environments make account management challenging and complex. A manual process for account management functions ad...
    Rule Medium Severity
  • SRG-APP-000024-AAA-000050

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules