Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36659 | WN08-00-000005-02 | SV-48276r1_rule | ECLP-1 | High |
Description |
---|
Using a privileged account to perform routine functions makes the computer vulnerable to malicious software inadvertently introduced during a session that has been granted full privileges. |
STIG | Date |
---|---|
Windows 8 Security Technical Implementation Guide | 2014-01-07 |
Check Text ( C-44954r1_chk ) |
---|
Verify each user with administrative privileges has been assigned a unique administrative account separate from their standard user account. The IAO will maintain a list of all users belonging to the Administrators group. If any of the following conditions are true, this is a finding: -Each SA does not have a unique userid dedicated for administering the system. -Each SA does not have a separate account for normal user tasks. |
Fix Text (F-41411r1_fix) |
---|
Ensure each user with administrative privilege has a separate account for user duties and one for privileged duties. |