800-53|IA-11

Title

RE-AUTHENTICATION

Description

The organization requires users and devices to re-authenticate when [Assignment: organization-defined circumstances or situations requiring re-authentication].

Supplemental

In addition to the re-authentication requirements associated with session locks, organizations may require re-authentication of individuals and/or devices in other situations including, for example: (i) when authenticators change; (ii), when roles change; (iii) when security categories of information systems change; (iv), when the execution of privileged functions occurs; (v) after a fixed period of time; or (vi) periodically.

Reference Item Details

Related: AC-11

Category: IDENTIFICATION AND AUTHENTICATION

Family: IDENTIFICATION AND AUTHENTICATION

Priority: P0

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.64 UBTU-24-300021UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.66 OL08-00-010380UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.67 OL08-00-010381UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.70 OL08-00-010384UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.71 OL08-00-010385UnixCIS Oracle Linux 8 STIG v1.0.0 CAT II
1.88 UBTU-22-432010UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.134 APPL-14-004022UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT II
1.138 APPL-14-004060UnixCIS Apple macOS 14 (Sonoma) STIG v1.0.0 CAT II
1.305 RHEL-09-432015UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.307 RHEL-09-432025UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.309 RHEL-09-432035UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.326 RHEL-09-611085UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.337 RHEL-09-611145UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
3.070 - The system is configured to permit storage of credentials or .NET Passports.WindowsDISA Windows Vista STIG v6r41
3.129 - User Account Control - Built In Admin Approval ModeWindowsDISA Windows Vista STIG v6r41
3.131 - User Account Control - Behavior of elevation prompt for standard users.WindowsDISA Windows Vista STIG v6r41
3.137 - User Account Control - Run all admins in Admin Approval ModeWindowsDISA Windows Vista STIG v6r41
5.2.4 Ensure users must provide password for escalationUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
5.2.4 Ensure users must provide password for escalationUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
5.2.4.1 (L1) Ensure 'Self service password reset enabled' is set to 'All'microsoft_azureCIS Microsoft 365 Foundations v5.0.0 L1 E5
5.2.4.1 (L1) Ensure 'Self service password reset enabled' is set to 'All'microsoft_azureCIS Microsoft 365 Foundations v5.0.0 L1 E3
5.2.5 Ensure users must re-authenticate for privilege escalationUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
5.2.5 Ensure users must re-authenticate for privilege escalationUnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Oracle Linux 8 v4.0.0 L1 Server
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Rocky Linux 8 v3.0.0 L1 Server
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS AlmaLinux OS 8 v4.0.0 L1 Server
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Red Hat Enterprise Linux 10 v1.0.1 L1 Workstation
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Server
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Oracle Linux 10 v1.0.0 L1 Server
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Red Hat Enterprise Linux 8 v4.0.0 L1 Server
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Red Hat Enterprise Linux 8 v4.0.0 L1 Workstation
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS AlmaLinux OS 10 v1.0.0 L1 Workstation
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS AlmaLinux OS 8 v4.0.0 L1 Workstation
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Oracle Linux 10 v1.0.0 L1 Workstation
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Rocky Linux 10 v1.0.0 L1 Workstation
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Rocky Linux 8 v3.0.0 L1 Workstation
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Red Hat Enterprise Linux 10 v1.0.1 L1 Server
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS Oracle Linux 8 v4.0.0 L1 Workstation
5.2.6 Ensure sudo timestamp_timeout is configuredUnixCIS AlmaLinux OS 10 v1.0.0 L1 Server
5.2.7 Ensure sudo authentication timeout is configuredUnixCIS Amazon Linux 2 STIG v2.0.0 STIG
5.2.7 Ensure sudo authentication timeout is configured - sudo command.UnixCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIG
5.2.9 Ensure sudo timestamp_timeout is configuredUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG
5.2.9 Ensure sudo timestamp_timeout is configuredUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 Server
5.2.9 Ensure sudo timestamp_timeout is configuredUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 L1 Workstation
5.2.11 Ensure pam_succeed_if does not exist in /etc/pam.d/sudoUnixCIS Red Hat Enterprise Linux 8 STIG v2.0.0 STIG
5.042 - Terminal Services is not configured to always prompt a client for passwords upon connection.WindowsDISA Windows Vista STIG v6r41
5.116 - Terminal Services / Remote Desktop Service - Prevent password saving in the Remote Desktop ClientWindowsDISA Windows Vista STIG v6r41
5.224 - Power Mgmt - Password Wake on BatteryWindowsDISA Windows Vista STIG v6r41
5.225 - Power Mgmt - Password Wake When Plugged InWindowsDISA Windows Vista STIG v6r41
7.2.10 (L1) Ensure reauthentication with verification code is restrictedmicrosoft_azureCIS Microsoft 365 Foundations v5.0.0 L1 E3