SV-222523r508029_rule
V-222523
SRG-APP-000149
APSC-DV-001550
CAT II
10
Configure the application to use an Alt. Token when providing network access to privileged application accounts.
Review the application documentation and interview the application administrator to identify application access methods.
Ask the application administrator to present both their primary CAC and their Alt. Token. Ask the application administrator to log on to the application using application relevant network based access methods. Attempt to use both CAC and Alt. Tokens to authenticate to the application.
Validate the application requests the user to input their CAC PIN and that they cannot perform administrative functions.
Have user logoff and reauthenticate with their Alt. Token and that they can perform administrative functions.
If the application allows administrative access to the application without requiring an Alt. Token, this is a finding.
V-222523
False
APSC-DV-001550
Review the application documentation and interview the application administrator to identify application access methods.
Ask the application administrator to present both their primary CAC and their Alt. Token. Ask the application administrator to log on to the application using application relevant network based access methods. Attempt to use both CAC and Alt. Tokens to authenticate to the application.
Validate the application requests the user to input their CAC PIN and that they cannot perform administrative functions.
Have user logoff and reauthenticate with their Alt. Token and that they can perform administrative functions.
If the application allows administrative access to the application without requiring an Alt. Token, this is a finding.
M
4093