SHPT-00-000100 - SharePoint must enforce dual authorization, based on organizational policies and procedures for organizationally defined privileged commands.

Information

An organization may see fit to define a policy stating certain commands contained within an application require dual authorization before they may be invoked. Dual authorization requires two distinct approving authorities to approve the use of the command prior to being invoked. When the organization defines a set of application related privileged commands requiring dual authorization, the application must support those organizational requirements.

Once an information management policy has been created, the metadata and security attributes created can be enforced using a workflow. However, as with most applications, privilege restrictions, such as dual authorizations cannot be set for the super account, Farm Administrator. When adding a workflow to a SharePoint library or list, this enforces a business process on all items in the library or list. A workflow describes the actions the system or users must perform on each item, such as obtain dual approvals.

Note: If many documents across different libraries require dual authorization, the site should consider creating a content type and adding this type as part of an information management policy.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Create an approval workflow for document libraries or documents which requires dual authorization.
1. On the site home page, click Site Actions, and then click Site Settings.
2. On the Site Settings page, in the Site Administration list, click Site libraries and lists.
3. On the Site Libraries and Lists page, select a library or list.
4. On the List Settings page, in the Permissions and Management list, click Workflow Settings.
5. On the Workflow Settings page, click Add a workflow.
6. Follow the directions of the workflow wizard to create an approval workflow that requires dual approval for the documents stored in the selected library.

See Also

https://iasecontent.disa.mil/stigs/zip/U_MS_SharePoint_2010_V1R9_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(2), CAT|II, CCI|CCI-000021, Rule-ID|SV-36114r2_rule, STIG-ID|SHPT-00-000100, Vuln-ID|V-27996

Plugin: Windows

Control ID: 0bd85027ca54e1787d2e7ab611af84eba569b80bf748f0e3813c8f949fbea1a8