Check: SRG-APP-000815-AAA-000140
AAA Services SRG:
SRG-APP-000815-AAA-000140
(in versions v2 r2 through v2 r1)
Title
AAA Services must be configured to require users to be individually authenticated before granting access to the shared accounts or resources. (Cat II impact)
Discussion
Individual authentication prior to shared group authentication mitigates the risk of using group accounts or authenticators.
Check Content
Verify AAA Services is configured to require users to be individually authenticated before granting access to the shared accounts or resources. If AAA Services is not configured to require users to be individually authenticated before granting access to the shared accounts or resources, this is a finding.
Fix Text
Configure AAA Services to require users to be individually authenticated before granting access to the shared accounts or resources.
Additional Identifiers
Rule ID: SV-263531r982389_rule
Vulnerability ID: V-263531
Group Title: SRG-APP-000815
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-004045 |
Require users to be individually authenticated before granting access to the shared accounts or resources. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |