Check: AXOS-00-000045
Axonius Federal Systems Ax-OS STIG:
AXOS-00-000045
(in versions v1 r2 through v1 r1)
Title
Ax-OS must use multifactor authentication for network access to the customer account. (Cat I impact)
Discussion
Without the use of multifactor authentication, the ease of access to privileged functions is greatly increased. Multifactor authentication requires using two or more factors to achieve authentication. Factors include: (i) something a user knows (e.g., password/PIN); (ii) something a user has (e.g., cryptographic identification device, token); or (iii) something a user is (e.g., biometric). A privileged account is defined as an information system account with authorizations of a privileged user. Network access is defined as access to an information system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, or the internet).
Check Content
Have the system administrator (SA) demonstrate accessing the Axonius Toolbox (accessed via Secure Shell [SSH]). Verify the SA is using a password-protected SSH key to log in to the system. If the SA is not using a password-protected SSH key to log in to the system, this is a finding.
Fix Text
From the Axonius Toolbox (accessed via SSH) Main Actions Menu, select the following options: System Actions >> Update customer account SSH key Follow the on-screen prompts to configure key-based authentication.
Additional Identifiers
Rule ID: SV-276009r1122677_rule
Vulnerability ID: V-276009
Group Title: SRG-APP-000149
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-000765 |
Implement multifactor authentication for access to privileged accounts. |
Controls
| Number | Title |
|---|---|
| IA-2(1) |
Multi-factor Authentication to Privileged Accounts |