SV-93619r1_rule
V-78913
SRG-OS-000123-GPOS-00064
IBMZ-VM-000860
CAT II
10
Develop a policy and process to remove or disable emergency accounts after a crisis has been resolved or 72 hours.
Ensure that all emergency accounts are disabled after a crisis has been resolved or 72 hours.
Ask the system administrator (SA) for a documented process to remove or disable emergency accounts after a crisis has been resolved or 72 hours.
If there is no documented process, this is a finding.
If there are emergency accounts enabled check date/time of resolution of last crisis event.
If date/time is greater than 72 hours, this is a finding.
V-78913
False
IBMZ-VM-000860
Ask the system administrator (SA) for a documented process to remove or disable emergency accounts after a crisis has been resolved or 72 hours.
If there is no documented process, this is a finding.
If there are emergency accounts enabled check date/time of resolution of last crisis event.
If date/time is greater than 72 hours, this is a finding.
M
3211