Rule ID
SV-239840r879589_rule
Version
V1R2
CCIs
To assure accountability and prevent unauthorized access, application server users must be uniquely identified and authenticated. This is typically accomplished via the use of a user store that is either local (OS-based) or centralized (LDAP) in nature. To ensure support to the enterprise, the authentication must utilize an enterprise solution.
Obtain the site configuration control policy from the ISSO. Review site procedures to determine if an enterprise management system is used to uniquely identify and authenticate users. If an enterprise management solution is not used, this is a finding.
Configure vROps to use an enterprise user management system and document this in the site configuration control policy.