UCF STIG Viewer Logo

The IDPS must enforce a DAC policy that includes or excludes access to the granularity of a single user.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000307-IDPS-000038 SRG-NET-000307-IDPS-000038 SRG-NET-000307-IDPS-000038_rule Low
Description
Access control policies (e.g., identity-based policies, role-based policies, etc) and access enforcement mechanisms (e.g., access control lists, policy maps, cryptography) are employed by organizations to control access between users (or processes acting on behalf of users) and objects (e.g., devices, data, destination addresses, etc.) within in the network. This applies to locally defined accounts where the user management functionality is part of the IDPS application. This control does not negate the use of security groups for assigning access control to each member. Without granular DAC policies, access control and enforcement mechanisms will not prevent unauthorized access to account information, system logs, and other files.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43156_chk )
Verify the site has configured the IDPS to implement an access control policy that grants access to objects to the granularity of the single user.

If the system does not enforce a DAC policy that includes or excludes access to the granularity of a single user, this is a finding.
Fix Text (F-43156_fix)
Configure the IDPS to use an access control policy that includes or excludes access to the granularity of a single user.