CCI-000804
CCI-000804 Definition
Status | |
Type | CheckType.technical |
Master Assessment Datasheet
Implementation Guidance
The organization being inspected/assessed configures the information system to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users). For information system components that have applicable STIGs or SRGs, the organization being inspected/assessed must comply with the STIG/SRG guidance that pertains to CCI 804.
Validation Procedures
The organization conducting the inspection/assessment examines the information system to ensure the organization being inspected/assessed configures the information system to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users). For information system components that have applicable STIGs or SRGs, the organization conducting the inspection/assessment evaluates the components to ensure that the organization being inspected/assessed has configured the information system in compliance with the applicable STIGs and SRGs pertaining to CCI 804.
DISA Compelling Evidence
1) Provide SOP/TTP documenting configuration of the information system to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users) **Note: Verify information system components that have applicable STIGs or SRGs comply with the STIG/SRG guidance that pertains to CCI 804. For Windows 2008 R2, also be sure to: Analyze the system using the Security Configuration and Analysis snap-in. Expand the Security Configuration and Analysis tree view. Navigate to Local Policies -> Security Options. the value for “Accounts: Guest account status” should be set to “Disabled”