Rule ID
SV-288142r1252912_rule
Version
V1R0.1
CCIs
Without mapping the certificate used to authenticate to the user account, the ability to determine the identity of the individual user or group will not be available for forensic analysis.
Review the application documentation and deployed configuration to determine whether the application's PKI authentication mechanism maps the authenticated identity to the individual user or group account. If the application's PKI authentication mechanism does not map the authenticated identity to the individual user or group account, this is a finding.
Configure the application's PKI authentication mechanism to map the authenticated identity to the individual user or group account.