SV-223468r533198_rule
V-223468
SRG-OS-000480-GPOS-00227
ACF2-ES-000500
CAT II
10
Review security procedures for defining LOGONIDs and develop documentation of requirements for the LOGONID associated with the REFRESH attribute.
Example:
When the ISSO determines it necessary to refresh the ACF2 global options, the ISSO will do the following:
-Activate the REFRESH ID with the following setting(s):
NOSUSPEND
NOPSWD EXP
PASSWORD(new password)
-Instruct Operations to perform the REFRESH.
-Deactivate the REFRESH ID with the following setting:
SUSPEND
From the ACF Command screen enter:
SET LID
LIST IF(REFRESH)
If procedures exist to utilize the logonid with the REFRESH attribute to refresh ACF2 global options, this is not a finding.
Example:
When the ISSO determines it necessary to refresh the ACF2 global options, the ISSO will do the following:
-Activate the REFRESH ID with the following setting(s):
NOSUSPEND
NOPSWD EXP
PASSWORD(new password)
-Instruct Operations to perform the REFRESH.
-Deactivate the REFRESH ID with the following setting:
SUSPEND
If no procedures exist in accordance with the STIG requirements to utilize the logonid with the REFRESH attribute to refresh ACF2 global options, this is a finding.
V-223468
False
ACF2-ES-000500
From the ACF Command screen enter:
SET LID
LIST IF(REFRESH)
If procedures exist to utilize the logonid with the REFRESH attribute to refresh ACF2 global options, this is not a finding.
Example:
When the ISSO determines it necessary to refresh the ACF2 global options, the ISSO will do the following:
-Activate the REFRESH ID with the following setting(s):
NOSUSPEND
NOPSWD EXP
PASSWORD(new password)
-Instruct Operations to perform the REFRESH.
-Deactivate the REFRESH ID with the following setting:
SUSPEND
If no procedures exist in accordance with the STIG requirements to utilize the logonid with the REFRESH attribute to refresh ACF2 global options, this is a finding.
M
4100