Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-16847 | APP6210 | SV-17847r1_rule | IAAC-1 | Medium |
Description |
---|
A comprehensive account management process will ensure that only authorized users can gain access to applications and that individual accounts designated as inactive, suspended, or terminated are promptly deactivated. Such a process greatly reduces the risk that accounts will be misused, hijacked, or data compromised. |
STIG | Date |
---|---|
Application Security and Development STIG | 2014-04-03 |
Check Text ( C-17860r1_chk ) |
---|
Interview the application representative to verify that a documented process exists for user and system account creation, termination, and expiration. Obtain a list of recently departed personnel and verify that their accounts were removed or deactivated on all systems in a timely manner (e.g., less than two days). 1) If a documented account management process does not exist or unauthorized users have active accounts, it is a finding. |
Fix Text (F-17169r1_fix) |
---|
Establish an account management process. |