800-53|AC-2(2)

Title

REMOVAL OF TEMPORARY / EMERGENCY ACCOUNTS

Description

The information system automatically [Selection: removes; disables] temporary and emergency accounts after [Assignment: organization-defined time period for each type of account].

Supplemental

This control enhancement requires the removal of both temporary and emergency accounts automatically after a predefined period of time has elapsed, rather than at the convenience of the systems administrator.

Reference Item Details

Category: ACCESS CONTROL

Parent Title: ACCOUNT MANAGEMENT

Family: ACCESS CONTROL

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AIX7-00-001001 - AIX must automatically remove or disable temporary user accounts after 72 hours or sooner.UnixDISA STIG AIX 7.x v2r9
AIX7-00-001014 - The AIX system must automatically remove or disable emergency accounts after the crisis is resolved or 72 hours.UnixDISA STIG AIX 7.x v2r9
AOSX-13-000110 - The macOS system must automatically remove or disable temporary user accounts after 72 hours.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-13-000115 - The macOS system must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours.UnixDISA STIG Apple Mac OSX 10.13 v2r5
AOSX-14-000012 - The macOS system must automatically remove or disable temporary user accounts after 72 hours.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-000013 - The macOS system must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours.UnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-15-000012 - The macOS system must automatically remove or disable temporary and emergency user accounts after 72 hours.UnixDISA STIG Apple Mac OSX 10.15 v1r10
APPL-11-000012 - The macOS system must automatically remove or disable temporary and emergency user accounts after 72 hours.UnixDISA STIG Apple macOS 11 v1r5
APPL-11-000012 - The macOS system must automatically remove or disable temporary and emergency user accounts after 72 hours.UnixDISA STIG Apple macOS 11 v1r8
APPL-12-000012 - The macOS system must automatically remove or disable temporary and emergency user accounts after 72 hours.UnixDISA STIG Apple macOS 12 v1r8
APPL-13-000012 - The macOS system must automatically remove or disable temporary and emergency user accounts after 72 hours.UnixDISA STIG Apple macOS 13 v1r3
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Automatically Remove or Disable Temporary or Emergency User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Automatically Remove or Disable Temporary or Emergency User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Automatically Remove or Disable Temporary or Emergency User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - All Profiles
Big Sur - Automatically Remove or Disable Temporary or Emergency User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Automatically Remove or Disable Temporary or Emergency User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 Moderate
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - CNSSI 1253
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - 800-53r4 High
Big Sur - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Automatically Remove or Disable Temporary or Emergency User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Automatically Remove or Disable Temporary or Emergency User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Automatically Remove or Disable Temporary or Emergency User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Automatically Remove or Disable Temporary User Accounts within 72 HoursUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
ESXI-67-000001 - Access to the ESXi host must be limited by enabling Lockdown Mode.VMwareDISA STIG VMware vSphere 6.7 ESXi v1r3
ESXI-70-000001 - Access to the ESXi host must be limited by enabling lockdown mode.VMwareDISA STIG VMware vSphere 7.0 ESXi v1r2
F5BI-DM-000015 - The BIG-IP appliance must automatically remove or disable temporary user accounts after 72 hours.F5DISA F5 BIG-IP Device Management STIG v2r3
F5BI-DM-000149 - The BIG-IP appliance must be configured to automatically remove or disable emergency accounts after 72 hours.F5DISA F5 BIG-IP Device Management STIG v2r3
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r4 Moderate
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Automatically Remove or Disable Emergency Accounts within 72 HoursUnixNIST macOS Monterey v1.0.0 - All Profiles