SV-95147r1_rule
V-80443
SRG-APP-000317
BROM-00-000690
CAT II
10
Modify the password for the Account of Last Resort.
1. Using the management console, navigate to "Settings".
2. Select "Users".
3. Click on the local account name representing the Account of Last Resort.
4. In the "Edit User" section, enter and confirm the new password.
5. Click "Save Settings".
If the Account of Last Resort has been removed after installation and configuration per vendor-recommended best practice (BROM-00-000300), either create a new account and password or change the password.
If the Account of Last Resort has been removed after installation and configuration per vendor-recommended best practice (BROM-00-000300), this is not a finding.
Examine the site's documentation. Verify there is a documented procedure for changing the password for the Account of Last Resort when an individual with knowledge of the password leaves the group. An acceptable practice is to either create a new account and password each time or change the password.
If a procedure for changing the password for the Account of Last Resort when an individual with knowledge of the password leaves the group is not documented or implemented, this is a finding.
V-80443
False
BROM-00-000690
If the Account of Last Resort has been removed after installation and configuration per vendor-recommended best practice (BROM-00-000300), this is not a finding.
Examine the site's documentation. Verify there is a documented procedure for changing the password for the Account of Last Resort when an individual with knowledge of the password leaves the group. An acceptable practice is to either create a new account and password each time or change the password.
If a procedure for changing the password for the Account of Last Resort when an individual with knowledge of the password leaves the group is not documented or implemented, this is a finding.
M
3375