UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The application server must disable accounts when the accounts are no longer associated to a user.


Overview

Finding ID Version Rule ID IA Controls Severity
V-263549 SRG-APP-000705-AS-000110 SV-263549r981699_rule Medium
Description
Disabling expired, inactive, or otherwise anomalous accounts supports the concepts of least privilege and least functionality, which reduce the attack surface of the system.
STIG Date
Application Server Security Requirements Guide 2024-05-28

Details

Check Text ( C-67449r981697_chk )
Verify the application server disables accounts when the accounts are no longer associated to a user.

If the application server does not disable accounts when the accounts are no longer associated to a user, this is a finding.
Fix Text (F-67357r981698_fix)
Configure the application server to disable accounts when the accounts are no longer associated to a user.