STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288142

CAT II (Medium)

The application must map the authenticated identity to the individual user or group account for Public Key Infrastructure (PKI)-based authentication.

Rule ID

SV-288142r1252912_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-000187

Discussion

Without mapping the certificate used to authenticate to the user account, the ability to determine the identity of the individual user or group will not be available for forensic analysis.

Check Content

Review the application documentation and deployed configuration to determine whether the application's PKI authentication mechanism maps the authenticated identity to the individual user or group account.

If the application's PKI authentication mechanism does not map the authenticated identity to the individual user or group account, this is a finding.

Fix Text

Configure the application's PKI authentication mechanism to map the authenticated identity to the individual user or group account.