Monterey - Require users to reauthenticate when changing authenticators

Information

Without reauthentication, users may access resources or perform tasks for which they do not have authorization. When operating systems provide the capability to change user authenticators, it is critical the user reauthenticate.

Solution

The technology inherently meets this requirement. No fix is required.

See Also

https://github.com/usnistgov/macos_security

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-11, CCE|CCE-90988-7, CCI|CCI-002038

Plugin: Unix

Control ID: c5619c5679bc1de829a72de90dbd40028e6df3429c9444f0a0547bf355ca80c2