STIGQter STIGQter: STIG Summary: Application Security and Development Security Technical Implementation Guide Version: 5 Release: 1 Benchmark Date: 23 Oct 2020:

The application must automatically remove or disable temporary user accounts 72 hours after account creation.

DISA Rule

SV-222409r508029_rule

Vulnerability Number

V-222409

Group Title

SRG-APP-000024

Rule Version

APSC-DV-000300

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure temporary accounts to be automatically removed or disabled after 72 hours after account creation.

Check Contents

If official documentation exist that disallows the use of temporary user accounts within the application, this requirement is not applicable.

Examine the application documentation or interview the application representative to identify how the application users are managed.

Navigate to the screen where user accounts are configured.

Create a test account and determine if there is a setting to specify the user account as being temporary in nature.

Determine if there is an available setting to expire the account after a period of time.

If the application has no ability to specify a user account as being temporary in nature, or if the account has no ability to automatically disable or remove the account after 72 hours after account creation, this is a finding.

Vulnerability Number

V-222409

Documentable

False

Rule Version

APSC-DV-000300

Severity Override Guidance

If official documentation exist that disallows the use of temporary user accounts within the application, this requirement is not applicable.

Examine the application documentation or interview the application representative to identify how the application users are managed.

Navigate to the screen where user accounts are configured.

Create a test account and determine if there is a setting to specify the user account as being temporary in nature.

Determine if there is an available setting to expire the account after a period of time.

If the application has no ability to specify a user account as being temporary in nature, or if the account has no ability to automatically disable or remove the account after 72 hours after account creation, this is a finding.

Check Content Reference

M

Target Key

4093

Comments