SV-222412r508029_rule
V-222412
SRG-APP-000025
APSC-DV-000330
CAT II
10
Design the application so unessential user accounts are not created during installation. Disable or delete all unnecessary application user accounts.
Review the system documentation and identify any valid application accounts that are required in order for the application to operate. Accounts the application itself uses in order to function are not in scope for this requirement.
Have the application administrator generate a list of all application users. This should include relevant user metadata such as phone numbers or department identifiers.
Have the application administrator identify and validate all user accounts.
If any accounts cannot be validated and are deemed to be unnecessary, this is a finding.
V-222412
False
APSC-DV-000330
Review the system documentation and identify any valid application accounts that are required in order for the application to operate. Accounts the application itself uses in order to function are not in scope for this requirement.
Have the application administrator generate a list of all application users. This should include relevant user metadata such as phone numbers or department identifiers.
Have the application administrator identify and validate all user accounts.
If any accounts cannot be validated and are deemed to be unnecessary, this is a finding.
M
4093