WN08-00-000002 - Shared user accounts must not be permitted on the system.

Information

Shared accounts (accounts where two or more people log on with the same user identification) do not provide adequate identification and authentication. There is no way to provide for non-repudiation or individual accountability for system access and resource usage. Documentation must include a list of personnel that have access to each shared account.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Create or update shared accounts documentation that minimally contains the name of the shared account(s), the system(s) on which the accounts exist, and the individuals who have access to the accounts. Remove any shared accounts that do not meet the requirements.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_MS_Windows_8_and_8-1_V1R23_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-2, CAT|II, CCI|CCI-000764, Rule-ID|SV-48015r2_rule, STIG-ID|WN08-00-000002, Vuln-ID|V-1072

Plugin: Windows

Control ID: 6bfe17867516972990e951782230a7c04b8bf4bd2dd8ac4de621f9723a644812