STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288136

CAT I (High)

The application must use multifactor authentication (MFA).

Rule ID

SV-288136r1252911_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-000765CCI-000766CCI-004046CCI-000778CCI-001953CCI-001954CCI-002009CCI-002010CCI-004046CCI-004047

Discussion

Without the use of MFA, the ease of access to privileged functions is greatly increased. MFA requires the use of two or more factors to achieve authentication. Factors include: (i) Something a user knows (e.g., password/PIN); (ii) Something a user has (e.g., cryptographic identification device, token); or (iii) Something a user is (e.g., biometric). The current DoW multifactor solution is the common access card (CAC). Other DoW or authorizing official (AO)-approved solutions may be implemented.

Check Content

Review application documentation and configuration settings to determine if the application is using an approved MFA solution to authenticate organizational users.

If an approved MFA solution is not being used, this is a finding.

Fix Text

Configure the application to use an approved MFA solution to uniquely identify and authenticate organizational users.