SV-95145r1_rule
V-80441
SRG-APP-000316
BROM-00-000685
CAT II
10
Disable access for the user account by assigning a role with zero privileges enabled. A role that has zero privileges assigned to it must exist, along with a group that is assigned to the role.
1. From the management console, click on the arrow next to "Settings".
2. Click on "Users".
3. Select the user that has been identified for disabling.
4. Add the user to the group that is associated with the role that carries zero privileges.
5. Delete/remove all other groups for that user.
6. Click "Save".
Inspect the BEC user settings for a role with no privileges and a group that is tied to that role.
1. From the management console, click on the arrow next to "Settings".
2. Click on "Roles".
3. Identify and select the role that has no privileges assigned to it.
4. Inspect the "Role" settings to ensure that a group has been assigned.
If the BEC is not configured to immediately disconnect or disable remote access to the information system, this is a finding.
V-80441
False
BROM-00-000685
Inspect the BEC user settings for a role with no privileges and a group that is tied to that role.
1. From the management console, click on the arrow next to "Settings".
2. Click on "Roles".
3. Identify and select the role that has no privileges assigned to it.
4. Inspect the "Role" settings to ensure that a group has been assigned.
If the BEC is not configured to immediately disconnect or disable remote access to the information system, this is a finding.
M
3375