Check: FreeBSD-10-000540
FreeBSD 10:
FreeBSD-10-000540
(in version v1 r1)
Title
The operating system must use multifactor authentication for local access. (Cat II impact)
Discussion
To assure accountability, prevent unauthenticated access, and prevent misuse of the system, users must utilize multifactor authentication for local access. Multifactor authentication is defined as using two or more factors to achieve authentication. Factors include: 1) Something you know (e.g., password/PIN); 2) Something you have (e.g., cryptographic identification device or token); and 3) Something you are (e.g., biometric). Local access is defined as access to an organizational information system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network. The DoD CAC with DoD-approved PKI is an example of multifactor authentication. Satisfies: SRG-OS-000107-GPOS-00054, SRG-OS-000108-GPOS-00055, SRG-OS-000376-GPOS-00161, SRG-OS-000377-GPOS-00162
Check Content
Verify the operating system uses multifactor authentication for local access. If it does not, this is a finding. One possible tool for this is pcsc. Check if this is enabled in rc.conf: $ grep pcsc /etc/rc.conf If PCSCD is not enabled, check with the system administrator if there is another method of using multifactor authentication.
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-540
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000767 |
The information system implements multifactor authentication for local access to privileged accounts. |
CCI-000768 |
The information system implements multifactor authentication for local access to non-privileged accounts. |
CCI-001953 |
The information system accepts Personal Identity Verification (PIV) credentials. |
CCI-001954 |
The information system electronically verifies Personal Identity Verification (PIV) credentials. |