Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-97249 | ISEC-06-000660 | SV-106373r1_rule | High |
Description |
---|
The ISEC7 local account password complexity controls do not meet DoD requirements; therefore, admins have the capability to configure the account out of compliance, which could allow attacker to gain unauthorized access to the server and access to command MDM servers. |
STIG | Date |
---|---|
ISEC7 EMM Suite v6.x Security Technical Implementation Guide | 2019-09-05 |
Check Text ( C-96087r1_chk ) |
---|
Log in to the ISEC7 EMM Suite console. Navigate to Administration >> Configuration >> Account Management >> Users. Select Edit next to the local account Admin. Verify Login disabled has been selected. If Login disabled has not been selected, this is a finding. |
Fix Text (F-102931r1_fix) |
---|
Log in to the ISEC7 EMM Suite console. Navigate to Administration >> Configuration >> Account Management >> Users. Select Edit next to the local account Admin. Check Login disabled for the account. Click Save. |