CCI|CCI-000767

Title

The information system implements multifactor authentication for local access to privileged accounts.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIX7-00-003200 - The AIX operating system must use Multi Factor Authentication.UnixDISA STIG AIX 7.x v3r1
AMLS-NM-000220 - The Arista Multilayer Switch must use multifactor authentication for local access to privileged accounts.AristaDISA STIG Arista MLS DCS-7000 Series NDM v1r4
AOSX-14-003020 - The macOS system must use multifactor authentication for local and network access to privileged and non-privileged accounts - ChallengeResponseAuthenticationUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-003020 - The macOS system must use multifactor authentication for local and network access to privileged and non-privileged accounts - enforceSmartCardUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-003020 - The macOS system must use multifactor authentication for local and network access to privileged and non-privileged accounts - PasswordAuthenticationUnixDISA STIG Apple Mac OSX 10.14 v2r6
APPL-11-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.UnixDISA STIG Apple macOS 11 v1r8
APPL-12-003020 - The macOS system must use multifactor authentication for local access to privileged and non-privileged accounts.UnixDISA STIG Apple macOS 12 v1r9
APPL-13-003020 - The macOS system must use multifactor authentication for local access to privileged and nonprivileged accounts.UnixDISA STIG Apple macOS 13 v1r4
APPL-14-001150 - The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003020 - The macOS system must enforce smart card authentication.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003030 - The macOS system must allow smart card authentication.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003050 - The macOS system must enforce multifactor authentication for logon.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003051 - The macOS system must enforce multifactor authentication for the su command.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
APPL-14-003052 - The macOS system must enforce multifactor authentication for privilege escalation through the sudo command.UnixDISA Apple macOS 14 (Sonoma) STIG v2r2
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Low
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-171
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Low
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Enforce Smartcard AuthenticationUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 Low
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 Low
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
DKER-EE-002180 - SAML integration must be enabled in Docker Enterprise.UnixDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2
EDGE-00-000056 - Suggestions of similar web pages in the event of a navigation error must be disabled.WindowsDISA STIG Edge v2r2
ESXI-06-000012 - The SSH daemon must ignore .rhosts files.UnixDISA STIG VMware vSphere 6.x ESXi OS v1r5
ESXI-06-000040 - The system must use multifactor authentication for local access to privileged accounts.VMwareDISA STIG VMware vSphere 6.x ESXi v1r5
ESXI-65-000012 - The ESXi host SSH daemon must ignore .rhosts files.UnixDISA STIG VMware vSphere ESXi OS 6.5 v2r4
ESXI-65-000040 - The ESXi host must use multifactor authentication for local access to privileged accounts.VMwareDISA STIG VMware vSphere ESXi 6.5 v2r4
ESXI-67-000012 - The ESXi host SSH daemon must ignore .rhosts files.UnixDISA STIG VMware vSphere 6.7 ESXi OS v1r3
ESXI-67-000040 - The ESXi host must use multifactor authentication for local DCUI access to privileged accounts.VMwareDISA STIG VMware vSphere 6.7 ESXi v1r3
ESXI-70-000012 - The ESXi host Secure Shell (SSH) daemon must ignore '.rhosts' files.UnixDISA STIG VMware vSphere 7.0 ESXi OS v1r2
GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.MDMAirWatch - DISA Google Android 12 COPE v1r2
GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.MDMMobileIron - DISA Google Android 12 COBO v1r2
GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.MDMMobileIron - DISA Google Android 12 COPE v1r2
GOOG-12-007200 - Google Android 12 must be configured to disable trust agents.MDMAirWatch - DISA Google Android 12 COBO v1r2
GOOG-13-707200 - Google Android 13 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MDMMobileIron - DISA Google Android 13 BYOD v1r2
GOOG-13-707200 - Google Android 13 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MDMAirWatch - DISA Google Android 13 BYOD v1r2
GOOG-14-707200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MDMAirWatch - DISA Google Android 14 BYOAD v1r1
GOOG-14-707200 - Google Android 14 must be configured to disable trust agents - NOTE: This requirement is not applicable (NA) for specific biometric authentication factors included in the product's Common Criteria evaluation.MDMMobileIron - DISA Google Android 14 BYOAD v1r1