NET0465 - Authorized accounts must be assigned the least privilege level necessary to perform assigned duties.

Information

By not restricting authorized accounts to their proper privilege level, access to restricted functions may be allowed before authorized personell are trained or experienced enough to use those functions. Network disruptions or outages may occur due to mistakes made by inexperienced persons using accounts with greater privileges than necessary.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Configure authorized accounts with the least privilege rule. Each user will have access to only the privileges they require to perform their assigned duties.

See Also

https://iasecontent.disa.mil/stigs/zip/U_Network_Infrastructure_Router_L3_Switch_V8R29_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(1), CAT|II, Rule-ID|SV-15472r4_rule, STIG-ID|NET0465, Vuln-ID|V-3057

Plugin: Juniper

Control ID: e0cf6d1d69454ff924840aba3a83032ab26c4ecf80ddae14e1a2a2c23d7755cb