800-53|AC-2(2)

Title

REMOVAL OF TEMPORARY / EMERGENCY ACCOUNTS

Description

The information system automatically [Selection: removes; disables] temporary and emergency accounts after [Assignment: organization-defined time period for each type of account].

Supplemental

This control enhancement requires the removal of both temporary and emergency accounts automatically after a predefined period of time has elapsed, rather than at the convenience of the systems administrator.

Reference Item Details

Category: ACCESS CONTROL

Parent Title: ACCOUNT MANAGEMENT

Family: ACCESS CONTROL

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
F5BI-DM-000015 - The BIG-IP appliance must automatically remove or disable temporary user accounts after 72 hours.F5DISA F5 BIG-IP Device Management STIG v2r3
F5BI-DM-000149 - The BIG-IP appliance must be configured to automatically remove or disable emergency accounts after 72 hours.F5DISA F5 BIG-IP Device Management STIG v2r3
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
OL07-00-010271 - The Oracle Linux operating system must automatically expire temporary accounts within 72 hours.UnixDISA Oracle Linux 7 STIG v3r1
OL08-00-020270 - OL 8 must automatically expire temporary accounts within 72 hours.UnixDISA Oracle Linux 8 STIG v2r2
RHEL-07-010271 - The Red Hat Enterprise Linux operating system must automatically expire temporary accounts within 72 hours.UnixDISA Red Hat Enterprise Linux 7 STIG v3r15
RHEL-08-020270 - RHEL 8 must automatically expire temporary accounts within 72 hours.UnixDISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-09-411040 - RHEL 9 must automatically expire temporary accounts within 72 hours.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
SLES-12-010331 - The SUSE operating system must automatically expire temporary accounts within 72 hours.UnixDISA SLES 12 STIG v3r1
SLES-15-020061 - The SUSE operating system must automatically expire temporary accounts within 72 hours.UnixDISA SLES 15 STIG v2r2
SOL-11.1-040020 - The operating system must automatically terminate temporary accounts within 72 hours.UnixDISA STIG Solaris 11 SPARC v3r1
SOL-11.1-040020 - The operating system must automatically terminate temporary accounts within 72 hours.UnixDISA STIG Solaris 11 X86 v3r1
UBTU-16-010200 - Emergency administrator accounts must never be automatically removed or disabled.UnixDISA STIG Ubuntu 16.04 LTS v2r3
UBTU-18-010447 - The Ubuntu operating system must automatically expire temporary accounts within 72 hours.UnixDISA STIG Ubuntu 18.04 LTS v2r15
UBTU-20-010410 - The Ubuntu operating system must automatically expire temporary accounts within 72 hours.UnixDISA STIG Ubuntu 20.04 LTS v2r1