WPAW-00-000100 - Administrators of high-value IT resources must complete required training.

Information

Required training helps to mitigate the risk of administrators not following required procedures. High-value IT resources are the most important and critical IT resources within an organization. They contain the most sensitive data in an organization, perform the most critical tasks of an organization, or have access to and can control all or nearly all IT resources within an organization. Requiring a PAW used exclusively for remote administrative management of designated high-value IT resources, including servers, workstations, directory services, applications, databases, and network components, will provide a separate 'channel' for the performance of administrative tasks on high-value IT resources and isolate these functions from the majority of threats and attack vectors found on higher-risk standard client systems. A main security architectural construct of a PAW is to remove non-administrative applications and functions from the PAW. Technical controls for securing high-value IT resources will be ineffective if administrators are not aware of key security requirements.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Add the following topics to initial and annual update training modules for system administrators of high-value IT resources:

- Remotely manage high-value IT resources only via a PAW.
- Administrative accounts will not be used for non-administrative functions (for example, read email, browse Internet).

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_PAW_V3R1_STIG.zip

Item Details

Category: AWARENESS AND TRAINING, CONFIGURATION MANAGEMENT

References: 800-53|AT-1a.1., 800-53|CM-6b., CAT|III, CCI|CCI-000101, CCI|CCI-000366, Rule-ID|SV-243442r991589_rule, STIG-ID|WPAW-00-000100, STIG-Legacy|SV-92847, STIG-Legacy|V-78141, Vuln-ID|V-243442

Plugin: Windows

Control ID: 08648d4fcf5bab519a962de435fed8e7d6d6ce8460cc0476ed4c6b8c68d39acb