SV-222410r508029_rule
V-222410
SRG-APP-000516
APSC-DV-000310
CAT III
10
Identify accounts that are created in an emergency situation and ensure procedures or processes are in place to prevent disabling or deleting the account while the emergency is underway.
Review the application documentation and interview the application administrator. Identify if emergency accounts are ever used.
If emergency accounts are not used, this requirement is not applicable.
If emergency accounts are used, validate a procedure, process, feature or function exists that will prevent the emergency account from being deleted or disabled during a crisis situation.
Examples include but are not limited to adding a flag to the account to ensure it is not deleted during a specified emergency period or placing the account in a designated group that is monitored and controlled in accordance with the crisis.
If a process, procedure, function or feature designed to prevent emergency accounts from being deleted or disabled during a crisis situation is not available, this is a finding.
V-222410
False
APSC-DV-000310
Review the application documentation and interview the application administrator. Identify if emergency accounts are ever used.
If emergency accounts are not used, this requirement is not applicable.
If emergency accounts are used, validate a procedure, process, feature or function exists that will prevent the emergency account from being deleted or disabled during a crisis situation.
Examples include but are not limited to adding a flag to the account to ensure it is not deleted during a specified emergency period or placing the account in a designated group that is monitored and controlled in accordance with the crisis.
If a process, procedure, function or feature designed to prevent emergency accounts from being deleted or disabled during a crisis situation is not available, this is a finding.
M
4093