UCF STIG Viewer Logo

The network element must enforce multifactor authentication for network access to non-privileged accounts where one of the factors is provided by a device separate from the network element being accessed.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000145-RTR-NA SRG-NET-000145-RTR-NA SRG-NET-000145-RTR-NA_rule Low
Description
Multifactor authentication is defined as: using two or more factors to achieve authentication. Factors include: (i) something you know (e.g., password/PIN); (ii) something you have (e.g., cryptographic identification device, token); or (iii) something you are (e.g., biometric). A non-privileged account is defined as: An information system account with authorizations of a regular or non-privileged user. When one of the authentication factors is provided by a device that is separate from the system that is being accessed, this is referred to as "out of band 2 factor authentication" (OOB2FA). This requirement is not applicable as by definition all network device accounts are privileged accounts.
STIG Date
Router Security Requirements Guide 2013-07-30

Details

Check Text ( C-SRG-NET-000145-RTR-NA_chk )
This requirement is NA for router.
Fix Text (F-SRG-NET-000145-RTR-NA_fix)
This requirement is NA for router.