STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288173

CAT II (Medium)

The application must terminate shared/group account credentials when members leave the group.

Rule ID

SV-288173r1252687_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-004045

Discussion

If shared/group account credentials are not terminated when individuals leave the group, the user that left the group can still gain access even though they are no longer authorized. A shared/group account credential is a shared form of authentication that allows multiple individuals to access the application using a single account. There may also be instances when specific user actions need to be performed on the information system without unique user identification or authentication. Examples of credentials include passwords and group membership certificates.

Check Content

Navigate to the account/role configuration function within the application.

Verify the application is configured to terminate shared/group account credentials when members leave the group. Otherwise, this is a finding.

Fix Text

Navigate to the account/role configuration function within the application.

Configure a policy to terminate shared/group account credentials when members leave the group.