Check: SRG-APP-000150-MAPP-NA
Mobile Application SRG:
SRG-APP-000150-MAPP-NA
(in version v1 r1)
Title
The application must use multifactor authentication for network access to non-privileged accounts. (Cat II impact)
Discussion
Multifactor authentication is defined as: using two or more factors to achieve authentication. Factors include: (i) something a user knows (e.g., password/PIN); (ii) something a user has (e.g., cryptographic identification device, token); or (iii) something a user is (e.g., biometric). A non-privileged account is defined as: An information system account with authorizations of a regular or non-privileged user. Network Access is defined as: Access to an information system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, Internet). Applications integrating with the DoD Active Directory and utilize the DoD CAC are examples of compliant multifactor authentication solutions. Rationale for non-applicability: Mobile applications that support remote access are not within the scope of this SRG.
Check Content
This requirement is NA for the MAPP SRG.
Fix Text
The requirement is NA. No fix is required.
Additional Identifiers
Rule ID: SV-46692r1_rule
Vulnerability ID: V-35405
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000766 |
Implement multifactor authentication for access to non-privileged accounts. |
Controls
Number | Title |
---|---|
IA-2(2) |
Network Access to Non-privileged Accounts |