SV-3057r6_rule
V-3057
Accounts assigned least privileges necessary to perform duties.
NET0465
CAT II
10
Configure authorized accounts with the least privilege rule. Each user will have access to only the privileges they require to perform their assigned duties.
Review the accounts authorized for access to the network device. Determine if the accounts are assigned the lowest privilege level necessary to perform assigned duties. User accounts must be set to a specific privilege level which can be mapped to specific commands or a group of commands. Authorized accounts should have the least privilege level unless deemed necessary for assigned duties.
If it is determined that authorized accounts are assigned to greater privileges than necessary, this is a finding.
V-3057
False
NET0465
Review the accounts authorized for access to the network device. Determine if the accounts are assigned the lowest privilege level necessary to perform assigned duties. User accounts must be set to a specific privilege level which can be mapped to specific commands or a group of commands. Authorized accounts should have the least privilege level unless deemed necessary for assigned duties.
If it is determined that authorized accounts are assigned to greater privileges than necessary, this is a finding.
M
Information Assurance Officer
1538