Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-004046
CCI
CCI|CCI-004046
Title
Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
APPL-14-001150 - The macOS system must disable password authentication for SSH.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-003020 - The macOS system must enforce smart card authentication.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-15-001150 - The macOS system must disable password authentication for SSH.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
APPL-15-003020 - The macOS system must enforce smart card authentication.
Unix
DISA Apple macOS 15 (Sequoia) STIG v1r1
JUEX-NM-000640 - The Juniper EX switch must be configured to use an authentication server for the purpose of authenticating users prior to granting administrative access.
Juniper
DISA Juniper EX Series Network Device Management v2r1
JUSX-DM-000095 - The Juniper SRX Services Gateway must be configured to use an authentication server to centrally manage authentication and logon settings for remote and nonlocal access.
Juniper
DISA Juniper SRX Services Gateway NDM v3r1
OL08-00-010390 - OL 8 must have the package required for multifactor authentication installed.
Unix
DISA Oracle Linux 8 STIG v2r1
OL08-00-010400 - OL 8 must implement certificate status checking for multifactor authentication.
Unix
DISA Oracle Linux 8 STIG v2r1
RHEL-08-010390 - RHEL 8 must have the packages required for multifactor authentication installed.
Unix
DISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-08-010400 - RHEL 8 must implement certificate status checking for multifactor authentication.
Unix
DISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-09-215075 - RHEL 9 must have the openssl-pkcs11 package installed.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-611165 - RHEL 9 must enable certificate based smart card authentication.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-611170 - RHEL 9 must implement certificate status checking for multifactor authentication.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-611175 - RHEL 9 must have the pcsc-lite package installed.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-611180 - The pcscd service on RHEL 9 must be active.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-611185 - RHEL 9 must have the opensc package installed.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
SLES-15-010460 - The SUSE operating system must have the packages required for multifactor authentication to be installed.
Unix
DISA SLES 15 STIG v2r1
SLES-15-010470 - The SUSE operating system must implement certificate status checking for multifactor authentication - which includes status information to an accepted trust anchor.
Unix
DISA SLES 15 STIG v2r1
SLES-15-020030 - The SUSE operating system must implement multifactor authentication for access to privileged accounts via pluggable authentication modules (PAM).
Unix
DISA SLES 15 STIG v2r1
TCAT-AS-001320 - Multifactor certificate-based tokens (CAC) must be used when accessing the management interface.
Unix
DISA STIG Apache Tomcat Application Server 9 v3r1 Middleware
UBTU-20-010063 - The Ubuntu operating system must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
Unix
DISA STIG Ubuntu 20.04 LTS v2r1
UBTU-22-612010 - Ubuntu 22.04 LTS must implement multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
Unix
DISA STIG Canonical Ubuntu 22.04 LTS v2r2