Audits
Settings
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Theme
Light
Dark
Auto
Help
Plugins
Overview
Plugins Pipeline
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Release Notes
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Links
Tenable Cloud
Tenable Community & Support
Tenable University
Settings
Theme
Light
Dark
Auto
Detections
Plugins
Overview
Plugins Pipeline
Release Notes
Newest
Updated
Search
Nessus Families
WAS Families
NNM Families
LCE Families
Tenable OT Security Families
About Plugin Families
Audits
Overview
Newest
Updated
Search Audit Files
Search Items
References
Authorities
Documentation
Download All Audit Files
Indicators
Overview
Search
Indicators of Attack
Indicators of Exposure
Analytics
CVEs
Overview
Newest
Updated
Search
Attack Path Techniques
Overview
Search
Audits
References
CCI
CCI-004895
CCI
CCI|CCI-004895
Title
Permit users to invoke the trusted communications path for communications between the user and the organization-defined security functions, including at a minimum, authentication and re-authentication.
Reference Item Details
Reference:
CCI - DISA Control Correlation Identifier
Category:
2024
Audit Items
View all Reference Audit Items
Name
Plugin
Audit Name
APPL-14-004022 - The macOS system must require users to reauthenticate for privilege escalation when using the 'sudo' command.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
APPL-14-004060 - The macOS system must configure sudoers timestamp type.
Unix
DISA Apple macOS 14 (Sonoma) STIG v2r1
CASA-VN-000350 - The Cisco ASA VPN gateway must be configured to renegotiate the IPsec Security Association after eight hours or less.
Cisco
DISA STIG Cisco ASA VPN v2r1
CASA-VN-000360 - The Cisco ASA VPN gateway must be configured to renegotiate the IKE security association after 24 hours or less.
Cisco
DISA STIG Cisco ASA VPN v2r1
CD12-00-010100 - PostgreSQL must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
PostgreSQLDB
DISA STIG Crunchy Data PostgreSQL DB v3r1
EPAS-00-008800 - The EDB Postgres Advanced Server must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
PostgreSQLDB
EnterpriseDB PostgreSQL Advanced Server DB v2r1
MADB-10-008200 - MariaDB must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
MySQLDB
DISA MariaDB Enterprise 10.x v2r1 DB
MYS8-00-010400 - The MySQL Database Server 8.0 must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
MySQLDB
DISA Oracle MySQL 8.0 v2r1 DB
OL08-00-010380 - OL 8 must require users to provide a password for privilege escalation.
Unix
DISA Oracle Linux 8 STIG v2r1
OL08-00-010381 - OL 8 must require users to reauthenticate for privilege escalation and changing roles.
Unix
DISA Oracle Linux 8 STIG v2r1
OL08-00-010384 - OL 8 must require reauthentication when using the 'sudo' command.
Unix
DISA Oracle Linux 8 STIG v2r1
OL08-00-010385 - The OL 8 operating system must not be configured to bypass password requirements for privilege escalation.
Unix
DISA Oracle Linux 8 STIG v2r1
PHTN-40-000133 The Photon operating system must require users to reauthenticate for privilege escalation.
Unix
DISA VMware vSphere 8.0 vCenter Appliance Photon OS 4.0 STIG v2r1
RHEL-08-010380 - RHEL 8 must require users to provide a password for privilege escalation.
Unix
DISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-08-010381 - RHEL 8 must require users to reauthenticate for privilege escalation.
Unix
DISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-08-010384 - RHEL 8 must require re-authentication when using the 'sudo' command - sudo command.
Unix
DISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-08-010385 - The RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation.
Unix
DISA Red Hat Enterprise Linux 8 STIG v2r1
RHEL-09-432015 - RHEL 9 must require reauthentication when using the 'sudo' command - sudo command.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-432025 - RHEL 9 must require users to reauthenticate for privilege escalation.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-432035 - RHEL 9 must restrict the use of the 'su' command - su command.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-611085 - RHEL 9 must require users to provide a password for privilege escalation.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
RHEL-09-611145 - RHEL 9 must not be configured to bypass password requirements for privilege escalation.
Unix
DISA Red Hat Enterprise Linux 9 STIG v2r2
SLES-15-010450 - The SUSE operating system must reauthenticate users when changing authenticators, roles, or escalating privileges.
Unix
DISA SLES 15 STIG v2r1
SLES-15-020102 - The SUSE operating system must require reauthentication when using the 'sudo' command - sudo command.
Unix
DISA SLES 15 STIG v2r1
SLES-15-020104 - The SUSE operating system must not be configured to bypass password requirements for privilege escalation.
Unix
DISA SLES 15 STIG v2r1
SPLK-CL-000010 - Splunk Enterprise idle session timeout must be set to not exceed 15 minutes.
Unix
DISA STIG Splunk Enterprise 8.x for Linux v2r1 STIG OS
SPLK-CL-000180 - Splunk Enterprise idle session timeout must be set to not exceed 15 minutes.
Splunk
DISA STIG Splunk Enterprise 7.x for Windows v3r1 REST API
TCAT-AS-000970 - Idle timeout for the management application must be set to 10 minutes.
Unix
DISA STIG Apache Tomcat Application Server 9 v3r1 Middleware
UBTU-20-010014 - The Ubuntu operating system must require users to reauthenticate for privilege escalation or when changing roles.
Unix
DISA STIG Ubuntu 20.04 LTS v2r1
UBTU-22-432010 - Ubuntu 22.04 LTS must require users to reauthenticate for privilege escalation or when changing roles.
Unix
DISA STIG Canonical Ubuntu 22.04 LTS v2r2
VCLU-80-000070 The vCenter Lookup service must set an inactive timeout for sessions.
Unix
DISA VMware vSphere 8.0 vCenter Appliance Lookup Service STIG v2r1
VCPF-80-000070 The vCenter Perfcharts service must set an inactive timeout for sessions.
Unix
DISA VMware vSphere 8.0 vCenter Appliance Perfcharts STIG v2r1
VCSA-80-000089 The vCenter Server must terminate vSphere Client sessions after 15 minutes of inactivity.
VMware
DISA VMware vSphere 8.0 vCenter STIG v2r1
VCST-80-000070 The vCenter STS service must set an inactive timeout for sessions.
Unix
DISA VMware vSphere 8.0 vCenter Appliance Secure Token Service (STS) STIG v2r1
VCUI-80-000070 The vCenter UI service must set an inactive timeout for sessions.
Unix
DISA VMware vSphere 8.0 vCenter Appliance User Interface (UI) STIG v2r1
WN10-CC-000145 - Users must be prompted for a password on resume from sleep (on battery).
Windows
DISA Windows 10 STIG v3r2
WN10-CC-000150 - The user must be prompted for a password on resume from sleep (plugged in).
Windows
DISA Windows 10 STIG v3r2
WN10-CC-000270 - Passwords must not be saved in the Remote Desktop Client.
Windows
DISA Windows 10 STIG v3r2
WN10-CC-000280 - Remote Desktop Services must always prompt a client for passwords upon connection.
Windows
DISA Windows 10 STIG v3r2
WN10-CC-000355 - The Windows Remote Management (WinRM) service must not store RunAs credentials.
Windows
DISA Windows 10 STIG v3r2
WN10-SO-000245 - User Account Control approval mode for the built-in Administrator must be enabled.
Windows
DISA Windows 10 STIG v3r2
WN10-SO-000255 - User Account Control must automatically deny elevation requests for standard users.
Windows
DISA Windows 10 STIG v3r2
WN10-SO-000270 - User Account Control must run all administrators in Admin Approval Mode, enabling UAC.
Windows
DISA Windows 10 STIG v3r2
WN11-CC-000145 - Users must be prompted for a password on resume from sleep (on battery).
Windows
DISA Windows 11 STIG v2r2
WN11-CC-000150 - The user must be prompted for a password on resume from sleep (plugged in).
Windows
DISA Windows 11 STIG v2r2
WN11-CC-000270 - Passwords must not be saved in the Remote Desktop Client.
Windows
DISA Windows 11 STIG v2r2
WN11-CC-000280 - Remote Desktop Services must always prompt a client for passwords upon connection.
Windows
DISA Windows 11 STIG v2r2
WN11-CC-000355 - The Windows Remote Management (WinRM) service must not store RunAs credentials.
Windows
DISA Windows 11 STIG v2r2
WN11-SO-000245 - User Account Control approval mode for the built-in Administrator must be enabled.
Windows
DISA Windows 11 STIG v2r2
WN11-SO-000255 - User Account Control must automatically deny elevation requests for standard users.
Windows
DISA Windows 11 STIG v2r2