STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 10 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← IA-8 (1) — Identification and Authentication (Non-Organizational Users)

CCI-002010

Definition

Electronically verify Personal Identity Verification-compliant credentials from other federal agencies.

Parent Control

IA-8 (1)Identification and Authentication (Non-Organizational Users)Identification and Authentication

Linked STIG Checks (30)

V-279055CAT IColdFusion must be using an enterprise solution for authentication.Adobe ColdFusion Security Technical Implementation GuideV-222993CAT IIMultifactor certificate-based tokens (CAC) must be used when accessing the management interface.Apache Tomcat Application Server 9 Security Technical Implementation GuideV-222558CAT IIThe application must electronically verify Personal Identity Verification (PIV) credentials from other federal agencies.Application Security and Development Security Technical Implementation GuideV-204807CAT IIThe application server must electronically verify Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.Application Server Security Requirements GuideV-272639CAT IICylanceON-PREM must be configured with a DOD issued certificate (or another authorizing official [AO]-approved certificate).Arctic Wolf CylanceON-PREM Security Technical Implementation GuideV-256844CAT ICompliance Guardian must use multifactor authentication for network access to privileged accounts.AvePoint Compliance Guardian Security Technical Implementation GuideV-283928CAT IFly Server must use an approved DoW enterprise identity, credential, and access management (ICAM) solution to uniquely identify and authenticate organizational users.AvePoint Fly Server Security Technical Implementation GuideV-283938CAT IFly Server must have no local accounts for the user interface.AvePoint Fly Server Security Technical Implementation GuideV-283939CAT IFly Server must have local authentication disabled.AvePoint Fly Server Security Technical Implementation GuideV-276012CAT IAx-OS must have no local accounts for the user interface.Axonius Federal Systems Ax-OS Security Technical Implementation GuideV-235780CAT IILDAP integration in Docker Enterprise must be configured.Docker Enterprise 2.x Linux/UNIX Security Technical Implementation GuideV-235821CAT IISAML integration must be enabled in Docker Enterprise.Docker Enterprise 2.x Linux/UNIX Security Technical Implementation GuideV-271034CAT IIDragos Platform must accept the DOD CAC or other PKI credential for identity management and personal authentication.Dragos Platform 2.x Security Technical Implementation GuideV-278400CAT IINGINX must accept Personal Identity Verification (PIV) credentials.F5 NGINX Security Technical Implementation GuideV-288136CAT IThe application must use multifactor authentication (MFA).General Application (GAPP) Security Requirements GuideV-288137CAT ILocal accounts must be removed after multifactor authentication (MFA) is configured. It is permissible for an emergency ("break glass") or service account to remain if absolutely required by the application. In this case, the associated complexity requirements apply.General Application (GAPP) Security Requirements GuideV-250335CAT IMultifactor authentication for network access to privileged accounts must be used.IBM WebSphere Liberty Server Security Technical Implementation GuideV-255865CAT IIThe WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.IBM WebSphere Traditional V9.x Security Technical Implementation GuideV-205575CAT IIThe Mainframe Product must electronically verify Personal Identity Verification (PIV) credentials from other federal agencies.Mainframe Product Security Requirements GuideV-254111CAT IINutanix AOS must accept Personal Identity Verification (PIV) credentials to access the management interface.Nutanix AOS 5.20.x Application Security Technical Implementation GuideV-279434CAT INutanix AOS must use multifactor authentication for access to privileged and nonprivileged accounts by enabling common access card (CAC) authentication.Nutanix Acropolis Application Server Security Technical Implementation GuideV-273204CAT IIOkta must be configured to accept Personal Identity Verification (PIV) credentials.Okta Identity as a Service (IDaaS) Security Technical Implementation GuideV-254093CAT IInnoslate must use multifactor authentication for network access to privileged and non-privileged accounts.SPEC Innovations Innoslate 4.x Security Technical Implementation GuideV-241005CAT IICommon Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.Tanium 7.0 Security Technical Implementation GuideV-234066CAT IICommon Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.Tanium 7.3 Security Technical Implementation GuideV-254897CAT IIMultifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.Tanium 7.x Application on TanOS Security Technical Implementation GuideV-253828CAT IIMultifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.Tanium 7.x Security Technical Implementation GuideV-256333CAT IIThe vCenter Server must enable revocation checking for certificate-based authentication.VMware vSphere 7.0 vCenter Security Technical Implementation GuideV-258919CAT IIThe vCenter Server must enable revocation checking for certificate-based authentication.VMware vSphere 8.0 vCenter Security Technical Implementation GuideV-269574CAT IXylok Security Suite must use a centralized user management solution.Xylok Security Suite 20.x Security Technical Implementation Guide