SV-215718r557355_rule
V-215718
SRG-NET-000138-ALG-000063
F5BI-AP-000073
CAT II
10
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable.
Verify the BIG-IP APM module is configured as follows:
Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles.
Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access.
Verify the Access Profile is configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
If the BIG-IP APM is not configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users), this is a finding.
V-215718
False
F5BI-AP-000073
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable.
Verify the BIG-IP APM module is configured as follows:
Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles.
Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access.
Verify the Access Profile is configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
If the BIG-IP APM is not configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users), this is a finding.
M
4018