UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The application server must notify appropriate individuals when accounts are terminated.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35449 SRG-APP-000294-AS-000178 SV-46736r1_rule Medium
Description
When application accounts are terminated, user accessibility is affected. Accounts are utilized for identifying individual application users or for identifying the application processes themselves. Application servers provide either a local user store or they can integrate with enterprise user stores like LDAP. As such, the application server must be able to notify designated individuals when accounts are terminated.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43803r1_chk )
Review AS product documentation and server configuration to determine if the AS is configured to notify staff when accounts are terminated. If the AS is not configured to meet this requirement, this is a finding.
Fix Text (F-39993r1_fix)
Configure the AS to automatically notify appropriate personnel when accounts are terminated.