SV-93591r1_rule
V-78885
SRG-OS-000118-GPOS-00060
IBMZ-VM-000650
CAT II
10
Develop a procedure that includes the following steps:
- Monitors the time since last logon.
- Checks all userIDs for inactivity more than 35 days.
- If found, the ISSO must suspend an account, but not delete it until it is verified by the local ISSO that the user no longer requires access.
- If verification is not received within 60 days, the account may be deleted.
Examine the procedure for disabling user accounts.
If the procedure performs the following steps, this is not a finding.
- Monitors the time since last logon.
- Checks all userIDs for inactivity more than 35 days.
- If found, the ISSO must suspend an account, but not delete it until it is verified by the local ISSO that the user no longer requires access.
- If verification is not received within 60 days, the account may be deleted.
V-78885
False
IBMZ-VM-000650
Examine the procedure for disabling user accounts.
If the procedure performs the following steps, this is not a finding.
- Monitors the time since last logon.
- Checks all userIDs for inactivity more than 35 days.
- If found, the ISSO must suspend an account, but not delete it until it is verified by the local ISSO that the user no longer requires access.
- If verification is not received within 60 days, the account may be deleted.
M
3211