Check: SRG-APP-000030-MAPP-NA
Mobile Application SRG:
SRG-APP-000030-MAPP-NA
(in version v1 r1)
Title
Applications must support the organizational requirement to automatically monitor on atypical usage of accounts. (Cat II impact)
Discussion
Atypical account usage is behavior that is not part of normal usage cycles. For example, user account activity occurring after hours or on weekends. A comprehensive account management process will ensure that an audit trail which documents the use of application user accounts and as required, notifies administrators and/or application owners exists. Such a process greatly reduces the risk that compromised user accounts will continue to be used by unauthorized persons and provides logging that can be used for forensic purposes. Rationale for non-applicability: This SRG applies to single-user applications. Single-user applications do not require user account management.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46442r1_rule
Vulnerability ID: V-35155
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001356 |
The organization monitors for atypical usage of information system accounts. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |