6.4.1 Ensure Trusted Contexts are Enabled

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

A Trusted Context object provides a means of enforcing encryption, assigning privileges based on roles, and ensuring that the actions performed on behalf of a user are performed in the context of the user's ID and privileges.

Rationale:

Creating Trusted Context objects to enforce encryption and assign roles will protect data in transit and limit access to information on a per user/role basis. Additionally, it ensures actions can be traced back to the user.

Solution

If there is no enabled Trusted Context object, create a Trusted Context object if needed and enable it.

See Also

https://workbench.cisecurity.org/benchmarks/10752