800-53|IA-2(3)

Title

LOCAL ACCESS TO PRIVILEGED ACCOUNTS

Description

The information system implements multifactor authentication for local access to privileged accounts.

Reference Item Details

Related: AC-6

Category: IDENTIFICATION AND AUTHENTICATION

Parent Title: IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS)

Family: IDENTIFICATION AND AUTHENTICATION

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.2.8 - /etc/security/user - 'sugroups=ALL su=true'UnixCIS AIX 5.3/6.1 L1 v1.1.0
AIX7-00-003200 - The AIX operating system must use Multi Factor Authentication.UnixDISA STIG AIX 7.x v3r1
APPL-11-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.UnixDISA STIG Apple macOS 11 v1r8
APPL-12-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.UnixDISA STIG Apple macOS 12 v1r9
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Low
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Low
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 Low
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 Low
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
EDGE-00-000056 - Suggestions of similar web pages in the event of a navigation error must be disabled.WindowsDISA STIG Edge v2r2
ESXI-06-000012 - The SSH daemon must ignore .rhosts files.UnixDISA STIG VMware vSphere 6.x ESXi OS v1r5
ESXI-65-000012 - The ESXi host SSH daemon must ignore .rhosts files.UnixDISA STIG VMware vSphere ESXi OS 6.5 v2r4
ESXI-67-000012 - The ESXi host SSH daemon must ignore .rhosts files.UnixDISA STIG VMware vSphere 6.7 ESXi OS v1r3
ESXI-70-000012 - The ESXi host Secure Shell (SSH) daemon must ignore '.rhosts' files.UnixDISA STIG VMware vSphere 7.0 ESXi OS v1r2
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - 800-171
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - 800-53r5 Low
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - 800-53r4 Low
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Enforce Smartcard AuthenticationUnixNIST macOS Monterey v1.0.0 - All Profiles
RHEL-09-255035 - RHEL 9 SSHD must accept public key authentication.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-611160 - RHEL 9 must use the common access card (CAC) smart card driver.UnixDISA Red Hat Enterprise Linux 9 STIG v2r2
SLES-12-030520 - The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).UnixDISA SLES 12 STIG v3r1
SLES-15-020030 - The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).UnixDISA SLES 15 STIG v2r2
UBTU-16-030840 - The Ubuntu operating system must implement smart card logins for multifactor authentication for access to accounts.UnixDISA STIG Ubuntu 16.04 LTS v2r3
UBTU-22-612010 - Ubuntu 22.04 LTS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.UnixDISA STIG Canonical Ubuntu 22.04 LTS v2r2