Information
Once an attacker establishes initial access to a system, the attacker often attempts to create a persistent method of reestablishing access. One way to accomplish this is for the attacker to simply create a new account. Notification of account creation is one method for mitigating this risk. A comprehensive account management process will ensure an audit trail that documents the creation of accounts and notifies administrators and the ISSO. Such a process greatly reduces the risk that accounts will be surreptitiously created and provides logging that can be used for forensic purposes.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Configure the BIG-IP appliance to use a properly configured authentication server to send a notification message to the administrators and ISSO when accounts are created.
Item Details
Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT
References: 800-53|AC-2(4), 800-53|CM-6b., CAT|II, CCI|CCI-000366, CCI|CCI-001683, Rule-ID|SV-228995r961863_rule, STIG-ID|F5BI-DM-000155, STIG-Legacy|SV-74607, STIG-Legacy|V-60177, Vuln-ID|V-228995
Control ID: 4bb7a884f9863426a86e5b77d77110ba2d5d372e14308eb98e67232eb53b6c4a