The application must use multifactor (Alt. Token) authentication for network access to privileged accounts.
An XCCDF Rule
Description
Multifactor authentication requires using two or more factors to achieve authentication and access. Factors include: (i) something a user knows (e.g., password/PIN); (ii) something a user has (e.g., cryptographic identification device, token); or (iii) something a user is (e.g., biometric). Multifactor authentication decreases the attack surface by virtue of the fact that attackers must obtain two factors, a physical token or a biometric and a PIN, in order to authenticate. It is not enough to simply steal a user's password to obtain access. A privileged account is defined as an information system account with authorizations of a privileged user. An Alt. Token is a separate CAC like token used specifically for administrative account access and serves as a separate identifier much like a separate user account. Network access is defined as access to an information system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, or the Internet).
- ID
- SV-222523r960972_rule
- Version
- APSC-DV-001550
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the application to use an Alt. Token when providing network access to privileged application accounts.