The application must use multifactor (Alt. Token) authentication for local access to privileged accounts.
An XCCDF Rule
Description
Multifactor authentication (MFA) requires using two or more factors to achieve authentication and access. Factors include: (i) something a user knows (e.g., password/PIN); (ii) something a user has (e.g., cryptographic identification device, token); or (iii) something a user is (e.g., biometric). MFA decreases the attack surface by virtue of the fact that attackers must obtain two factors, a physical token or a biometric and a PIN, in order to authenticate. It is not enough to simply steal a user's password to obtain access. A privileged account is defined as an information system account with authorizations of a privileged user. An Alt. Token is a separate CAC or token used specifically for administrative account access and serves as a separate identifier much like a separate user account. Local access is defined as access to an organizational information system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network.
- ID
- SV-222527r1015693_rule
- Version
- APSC-DV-001590
- Severity
- Medium
- References
- Updated
Remediation Templates
A Manual Procedure
Configure the application to only use Alt. Tokens when locally accessing privileged application accounts.