800-53|AC-2c.

Title

ACCOUNT MANAGEMENT

Description

Establishes conditions for group and role membership;

Reference Item Details

Category: ACCESS CONTROL

Family: ACCESS CONTROL

Baseline Impact: LOW,MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
2.2 Ensure the SharePoint farm service account (database access account) is configured with the minimum privileges for the local server.WindowsCIS Microsoft SharePoint 2016 OS v1.1.0
2.2 Ensure the SharePoint farm service account (database access account) is configured with the minimum privileges for the local server.WindowsCIS Microsoft SharePoint 2019 OS v1.0.0
5.4.3 Ensure default group for the root account is GID 0UnixCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0
5.4.3 Ensure default group for the root account is GID 0UnixCIS SUSE Linux Enterprise Workstation 11 L1 v2.1.1
5.4.3 Ensure default group for the root account is GID 0UnixCIS Amazon Linux v2.1.0 L1
5.4.3 Ensure default group for the root account is GID 0UnixCIS SUSE Linux Enterprise Server 11 L1 v2.1.1
5.4.3 Ensure default group for the root account is GID 0UnixCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0
5.5 Ensure access to the su command is restricted - wheel group contains rootUnixCIS Amazon Linux v2.1.0 L1
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Amazon Linux 2023 Server L1 v1.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Red Hat EL8 Server L1 v3.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Ubuntu Linux 20.04 LTS Workstation L1 v2.0.1
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Oracle Linux 8 Server L1 v3.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Red Hat Enterprise Linux 7 v4.0.0 L1 Workstation
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS CentOS Linux 7 v4.0.0 L1 Workstation
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Debian 10 Workstation L1 v2.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Amazon Linux 2 v3.0.0 L1
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Red Hat Enterprise Linux 7 v4.0.0 L1 Server
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Oracle Linux 7 v4.0.0 L1 Server
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS AlmaLinux OS 8 Server L1 v3.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS AlmaLinux OS 8 Workstation L1 v3.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Debian 10 Server L1 v2.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS CentOS Linux 7 v4.0.0 L1 Server
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Oracle Linux 7 v4.0.0 L1 Workstation
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Oracle Linux 8 Workstation L1 v3.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Red Hat EL8 Workstation L1 v3.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Rocky Linux 8 Server L1 v2.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Rocky Linux 8 Workstation L1 v2.0.0
6.2.3 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Ubuntu Linux 20.04 LTS Server L1 v2.0.1
6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Amazon Linux v2.1.0 L1
6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0
6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0
6.2.15 Ensure all groups in /etc/passwd exist in /etc/groupUnixCIS Google Container-Optimized OS v1.2.0 L2 Server
7.4 Set Default Group for root AccountUnixCIS Solaris 10 L1 v5.2
7.5 Change Home Directory for root AccountUnixCIS Solaris 10 L1 v5.2
8.6 Set default group for root accountUnixCIS Solaris 9 v1.3
9.5 Restrict Access to the su Command - 'wheel group contains root'UnixCIS Ubuntu 12.04 LTS Benchmark L1 v1.1.0
9.5 Restrict Access to the su Command - wheel group has membersUnixCIS Debian Linux 7 L1 v1.0.0
9.11 Check Groups in /etc/passwdUnixCIS Solaris 10 L1 v5.2
9.11 Check Groups in passwd(4)UnixCIS Solaris 11.1 L1 v1.0.0
9.11 Check Groups in passwd(4)UnixCIS Solaris 11 L1 v1.1.0
9.11 Check Groups in passwd(4)UnixCIS Solaris 11.2 L1 v1.1.0
10.3 Set Default Group for root AccountUnixCIS Debian Linux 7 L1 v1.0.0
12.03 Unix root group members on host - 'Disallow 'oracle' as a member of root group'UnixCIS v1.1.0 Oracle 11g OS L1
13.11 Check Groups in /etc/passwdUnixCIS Debian Linux 7 L1 v1.0.0
13.11 Check Groups in /etc/passwdUnixCIS Ubuntu 12.04 LTS Benchmark L1 v1.1.0
DG0005-ORACLE11 - Only necessary privileges to the host system should be granted to DBA OS accounts - 'Oracle instance DBA is only a member of ORA_{SID}_DBA and Users group'WindowsDISA STIG Oracle 11 Installation v9r1 Windows
Ensure access to the su command is restricted - wheel group contains rootUnixTenable Cisco Firepower Management Center OS Best Practices Audit
Ensure all groups in /etc/passwd exist in /etc/groupUnixTenable Cisco Firepower Management Center OS Best Practices Audit
Ensure default group for the root account is GID 0UnixTenable Cisco Firepower Management Center OS Best Practices Audit
GEN000850 - The system must restrict the ability to switch to the root user to members of a defined group.UnixDISA STIG AIX 5.3 v1r2