800-53|AC-2(11)

Title

USAGE CONDITIONS

Description

The information system enforces [Assignment: organization-defined circumstances and/or usage conditions] for [Assignment: organization-defined information system accounts].

Supplemental

Organizations can describe the specific conditions or circumstances under which information system accounts can be used, for example, by restricting usage to certain days of the week, time of day, or specific durations of time.

Reference Item Details

Category: ACCESS CONTROL

Parent Title: ACCOUNT MANAGEMENT

Family: ACCESS CONTROL

Baseline Impact: HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.1.1.1.2 Configure 'Enforce user logon restrictions'WindowsCIS Windows 2003 DC v3.1.0
1.1.1.1.1.2 Configure 'Enforce user logon restrictions'WindowsCIS Windows 2003 MS v3.1.0
1.1.10 Enforce user logon restrictionsWindowsCIS Windows 2008 SSLF v1.2.0
1.1.10 Enforce user logon restrictions - Domain ControllerWindowsCIS Windows 2008 Enterprise v1.2.0
1.3.1 Ensure 'Enforce user logon restrictions' is set to 'Enabled' (STIG DC only)WindowsCIS Microsoft Windows Server 2022 STIG v1.0.0 STIG DC
1.3.1 Ensure 'Enforce user logon restrictions' is set to 'Enabled' (STIG DC only)WindowsCIS Microsoft Windows Server 2019 STIG v2.0.0 STIG DC
1.3.1 Ensure 'Enforce user logon restrictions' is set to 'Enabled' (STIG DC only)WindowsCIS Microsoft Windows Server 2016 STIG v2.0.0 STIG DC
AD.4029_2008 - Kerberos user logon restrictions must be enforced.WindowsDISA Windows Server 2008 DC STIG v6r47
AD.4029_2008_R2 - Kerberos user logon restrictions must be enforced.WindowsDISA Windows Server 2008 R2 DC STIG v1r34
AOSX-14-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup - AuthenticationAuthorityUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup - DisableFDEAutologinUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup - FileVault UserUnixDISA STIG Apple Mac OSX 10.14 v2r6
APPL-11-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup - UserShellUnixDISA STIG Apple macOS 11 v1r8
APPL-11-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup - UserShellUnixDISA STIG Apple macOS 11 v1r5
APPL-11-000033 - The macOS system must be configured to disable password forwarding for FileVault2.UnixDISA STIG Apple macOS 11 v1r8
APPL-11-000033 - The macOS system must be configured to disable password forwarding for FileVault2.UnixDISA STIG Apple macOS 11 v1r5
APPL-12-000032 - The macOS system must be configured with dedicated user accounts to decrypt the hard disk upon startup.UnixDISA STIG Apple macOS 12 v1r8
APPL-12-000033 - The macOS system must be configured to disable password forwarding for FileVault2.UnixDISA STIG Apple macOS 12 v1r8
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Low
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Disable FileVault Automatic LoginUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Low
Big Sur - FileVault Authorized UsersUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - FileVault Authorized UsersUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - 800-53r5 Low
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - 800-53r4 Low
Catalina - Disable FileVault Automatic LoginUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - FileVault Authorized UsersUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - FileVault Authorized UsersUnixNIST macOS Catalina v1.5.0 - All Profiles
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - 800-53r4 Low
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - 800-53r5 Low
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - 800-171
Monterey - Disable FileVault Automatic LoginUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - FileVault Authorized UsersUnixNIST macOS Monterey v1.0.0 - All Profiles