UCF STIG Viewer Logo

The IDPS must use multi-factor authentication for network access to non-privileged accounts.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000140-IDPS-NA SRG-NET-000140-IDPS-NA SRG-NET-000140-IDPS-NA_rule Medium
Description
Multifactor authentication is defined as: using two or more factors to achieve authentication. Factors include: (i) something you know (e.g. password/PIN); (ii) something you have (e.g., cryptographic identification device, token); or (iii) something you are (e.g., biometric). A non-privileged account is defined as: An information system account with authorizations of a regular or non-privileged user. Network Access is defined as: Access to an information system by a user (or a process acting on behalf of a user) communicating through a network (e.g., local area network, wide area network, Internet). Non-privileged users are not authorized to authenticate to the sensors or management consoles.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43265_chk )
This requirement does not apply to IDPS.
Fix Text (F-43265_fix)
Not applicable for IDPS. No fix required.