Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-36666 | WN12-00-000006 | SV-51577r1_rule | ECLP-1 | Medium |
Description |
---|
If SAs are assigned to systems running operating systems for which they have no training, these systems are at additional risk of unintentional misconfiguration that may result in vulnerabilities or decreased availability of the system. |
STIG | Date |
---|---|
Windows Server 2012/2012 R2 Member Server Security Technical Implementation Guide | 2018-09-05 |
Check Text ( C-46840r2_chk ) |
---|
Determine whether the site has a policy that requires SAs be trained for all operating systems running on systems under their control. If the site does not have a policy requiring SAs be trained for all operating systems under their control, this is a finding. |
Fix Text (F-44706r1_fix) |
---|
Establish site policy that requires SAs be trained for all operating systems running on systems under their control. |