-
Notifications
You must be signed in to change notification settings - Fork 673
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
RHEL7 STIG: CCI-000016 The operating system must automatically remove or disable temporary user accounts after 72 hours. #70
Comments
AC-2 (2) |
@shawndwells can this be closed with the merging of #349? Seems like this should have auto-closed with the merge, but I just wanted to make sure that it wasn't open for another reason. |
not yet. looks like the CCE has been reused in RHEL6/7:
and likely the xccdf needs to be added to stig profile. I'll do this now. |
(p.s. @redhatrises thank you so much for helping to clear out the tickets!) |
@redhatrises updated and submitted PR for your review |
Add SLES-12-020510
CCI-000016 SRG-OS-000002 The operating system must automatically remove or disable temporary user accounts after 72 hours. "If temporary user accounts remain active when no longer needed or for an excessive period, these accounts may be used to gain unauthorized access. To mitigate this risk, automated termination of all temporary accounts must be set upon account creation.
Temporary accounts are established as part of normal account activation procedures when there is a need for short-term accounts without the demand for immediacy in account activation.
If temporary accounts are used, the operating system must be configured to automatically terminate these types of accounts after a DoD-defined time period of 72 hours.
To address access requirements, many operating systems may be integrated with enterprise level authentication/access mechanisms that meet or exceed access control policy requirements. "
The text was updated successfully, but these errors were encountered: