Rule ID
SV-288135r1252910_rule
Version
V1R0.1
To ensure accountability and prevent unauthenticated access, organizational users must be identified and authenticated to prevent potential misuse and compromise of the system. This is typically accomplished via the use of a user store, which is either local (OS-based) or centralized (LDAP, Active Directory) in nature. However, DODI 8520.03 now requires that applications use an approved DoW E-ICAM solution whenever the ICAM solution addresses information system needs. Where the ICAM solution has been evaluated and found to not meet the needs of information system owners, information system owners must reevaluate decisions to use locally managed solutions (LDAP, Active Directory) and transition to DoW enterprise ICAM solutions to the maximum extent possible as the E-ICAM solutions mature.
Review application documentation and configuration settings to determine if the application is using an approved E-ICAM solution to authenticate organizational users. If an approved E-ICAM solution is not being used, this is a finding. Note: If the site is currently using an enterprise solution (AAA Server) and has documented their plans to move to an approved E-ICAM solution, the severity of this control can be reduced to a CAT III.
Configure the application to use an approved E-ICAM solution to uniquely identify and authenticate organizational users.