SV-222409r508029_rule
V-222409
SRG-APP-000024
APSC-DV-000300
CAT II
10
Configure temporary accounts to be automatically removed or disabled after 72 hours after account creation.
If official documentation exist that disallows the use of temporary user accounts within the application, this requirement is not applicable.
Examine the application documentation or interview the application representative to identify how the application users are managed.
Navigate to the screen where user accounts are configured.
Create a test account and determine if there is a setting to specify the user account as being temporary in nature.
Determine if there is an available setting to expire the account after a period of time.
If the application has no ability to specify a user account as being temporary in nature, or if the account has no ability to automatically disable or remove the account after 72 hours after account creation, this is a finding.
V-222409
False
APSC-DV-000300
If official documentation exist that disallows the use of temporary user accounts within the application, this requirement is not applicable.
Examine the application documentation or interview the application representative to identify how the application users are managed.
Navigate to the screen where user accounts are configured.
Create a test account and determine if there is a setting to specify the user account as being temporary in nature.
Determine if there is an available setting to expire the account after a period of time.
If the application has no ability to specify a user account as being temporary in nature, or if the account has no ability to automatically disable or remove the account after 72 hours after account creation, this is a finding.
M
4093