CCI|CCI-000015

Title

Support the management of system accounts using (organization-defined automated mechanisms).

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIX7-00-001000 - AIX /etc/security/mkuser.sys.custom file must not exist unless it is needed for customizing a new user account.UnixDISA STIG AIX 7.x v3r1
AIX7-00-001016 - The regular users default primary group must be staff (or equivalent) on AIX.UnixDISA STIG AIX 7.x v3r1
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
CNTR-K8-000220 - The Kubernetes Controller Manager must create unique service accounts for each work payload.UnixDISA STIG Kubernetes v2r2
F5BI-DM-000013 - The BIG-IP appliance must provide automated support for account management functions.F5DISA F5 BIG-IP Device Management STIG v2r3
MD3X-00-000010 - MongoDB must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.UnixDISA STIG MongoDB Enterprise Advanced 3.x v2r3 OS
MD4X-00-001600 - MongoDB must integrate with an organization-level authentication/access mechanism providing account management and automation for all users, groups, roles, and any other principals.UnixDISA STIG MongoDB Enterprise Advanced 4.x v1r4 OS
Monterey - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Monterey v1.0.0 - 800-53r4 High
Monterey - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
Monterey - Employ Automated Mechanisms for Account Management FunctionsUnixNIST macOS Monterey v1.0.0 - CNSSI 1253
SPLK-CL-000020 - Splunk Enterprise must notify the system administrator (SA) and information system security officer (ISSO) when account events are received (creation, deletion, modification, or disabling) - creation, deletion, modification, or disabling.SplunkDISA STIG Splunk Enterprise 8.x for Linux v2r1 STIG REST API
SPLK-CL-000235 - Splunk Enterprise must notify analysts of applicable events for Tier 2 CSSP and JRSS only.SplunkDISA STIG Splunk Enterprise 7.x for Windows v3r1 REST API