Check: WSDP-NM-000108
IBM DataPower Network Device Management STIG:
WSDP-NM-000108
(in versions v1 r2 through v1 r1)
Title
The DataPower Gateway must require users to re-authenticate when privilege escalation or role changes occur. (Cat II impact)
Discussion
Without re-authentication, users may access resources or perform tasks for which they do not have authorization. When devices provide the capability to change security roles, it is critical the user re-authenticate. In addition to the re-authentication requirements associated with session locks, organizations may require re-authentication of individuals and/or devices in other situations, including (but not limited to) the following circumstances. (i) When authenticators change; (ii) When roles change; (iii) When security categories of information systems change; (iv) When the execution of privileged functions occurs; (v) After a fixed period of time; or (vi) Periodically. Within the DoD, the minimum circumstances requiring re-authentication are privilege escalation and role changes.
Check Content
Go to Status >> Main >> Active Users and ensure that the user is not currently logged on. If the user is logged in, it is a finding.
Fix Text
After making any account privilege changes, administrator must go to Status >> Main >> Active Users and disconnect the user's current session if they are currently logged on.
Additional Identifiers
Rule ID: SV-79653r1_rule
Vulnerability ID: V-65163
Group Title: SRG-APP-000389-NDM-000306
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002038 |
The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication. |
Controls
Number | Title |
---|---|
IA-11 |
Re-Authentication |