Check: SRG-APP-000389-UEM-000260
Unified Endpoint Management Agent SRG:
SRG-APP-000389-UEM-000260
(in version v1 r0.1)
Title
The UEM server must require users (administrators) to reauthenticate when roles change. (Cat II impact)
Discussion
Without reauthentication, users may access resources or perform tasks for which they do not have authorization. When applications provide the capability to change security roles or escalate the functional capability of the application, it is critical the user reauthenticate. In addition to the reauthentication requirements associated with session locks, organizations may require reauthentication of individuals and/or devices in other situations, including (but not limited to) the following circumstances. (i) When authenticators change; (ii) When roles change; (iii) When security categories of information systems change; (iv) When the execution of privileged functions occurs; (v) After a fixed period of time; or (vi) Periodically. Within the DoD, the minimum circumstances requiring reauthentication are privilege escalation and role changes.
Check Content
Verify the UEM server requires users (administrators) to reauthenticate when roles change. If the UEM server does not require users (administrators) to reauthenticate when roles change, this is a finding.
Fix Text
Configure the UEM server to require users (administrators) to reauthenticate when roles change.
Additional Identifiers
Rule ID: SRG-APP-000389-UEM-000260_rule
Vulnerability ID: SRG-APP-000389-UEM-000260
Group Title: SRG-APP-000389-UEM-000260
Expert Comments
CCIs
| Number | Definition |
|---|---|
| CCI-002038 |
The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication. |
Controls
| Number | Title |
|---|---|
| IA-11 |
Re-authentication |