Rule ID
SV-288137r1252644_rule
Version
V1R0.1
Without the use of MFA, the ease of access to privileged functions is greatly increased. MFA requires the use of two or more factors to achieve authentication. Factors include: (i) Something a user knows (e.g., password/PIN); (ii) Something a user has (e.g., cryptographic identification device, token); or (iii) Something a user is (e.g., biometric). The current DoW multifactor solution is the common access card (CAC). Other DoW or authorizing official (AO)-approved solutions may be implemented. To ensure MFA is used, access to local accounts must be removed.
Navigate to the local account configuration function within the application. Verify no local accounts exist. Otherwise, this is a finding. If a break glass or service account remains, this must be documented and approved by the AO. Otherwise, this is a finding.
Navigate to the local account configuration function within the application and remove all local accounts. For break glass or service accounts, apply the appropriate password complexity per policy.