800-53|IA-2(2)

Title

NETWORK ACCESS TO NON-PRIVILEGED ACCOUNTS

Description

The information system implements multifactor authentication for network access to non-privileged accounts.

Reference Item Details

Category: IDENTIFICATION AND AUTHENTICATION

Parent Title: IDENTIFICATION AND AUTHENTICATION (ORGANIZATIONAL USERS)

Family: IDENTIFICATION AND AUTHENTICATION

Baseline Impact: MODERATE,HIGH

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.2 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Privileged Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - List Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L2
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - Role Assignmentsmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L2
1.1.3 Ensure that 'Multi-Factor Auth Status' is 'Enabled' for all Non-Privileged Users - Role Definitionsmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L2
1.1.3.10.2 Set 'Network access: Allow anonymous SID/Name translation' to 'Disabled'WindowsCIS Windows 8 L1 v1.0.0
1.1.3.10.4 Configure 'Network access: Named Pipes that can be accessed anonymously'WindowsCIS Windows 8 L1 v1.0.0
1.1.4 Ensure that 'Allow users to remember multi-factor authentication on devices they trust' is Disabledmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.2 Ensure that Multi-Factor Authentication is 'Enabled' for All Non-Service AccountsGCPCIS Google Cloud Platform v2.0.0 L1
1.2.1 Set 'privilege 1' for local usersCiscoCIS Cisco IOS 17 L1 v2.0.0
1.2.1 Set 'privilege 1' for local users - 'No users with privileges 2-15'CiscoCIS Cisco IOS 16 L1 v2.0.0
1.2.3 Ensure that A Multi-factor Authentication Policy Exists for Administrative Groupsmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.2.4 Ensure that A Multi-factor Authentication Policy Exists for All Usersmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.2.5 Ensure Multi-factor Authentication is Required for Risky Sign-insmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.2.6 Ensure Multi-factor Authentication is Required for Azure Managementmicrosoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.3 Ensure that Security Key Enforcement is Enabled for All Admin AccountsGCPCIS Google Cloud Platform v2.0.0 L2
1.6 Ensure That 'Number of methods required to reset' is set to '2'microsoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
1.22 Ensure that 'Require Multi-Factor Authentication to register or join devices with Azure AD' is set to 'Yes'microsoft_azureCIS Microsoft Azure Foundations v2.0.0 L1
2.1 Ensure Authentication is configuredUnixCIS MongoDB 5 L1 OS Linux v1.2.0
2.1 Ensure Authentication is configuredUnixCIS MongoDB 7 L1 OS Linux v1.0.0
2.1 Ensure Authentication is configuredWindowsCIS MongoDB 4 L1 OS Windows v1.0.0
2.1 Ensure Authentication is configuredWindowsCIS MongoDB 3.6 L1 Windows Audit v1.1.0
2.1 Ensure Authentication is configuredUnixCIS MongoDB 3.6 L1 Unix Audit v1.1.0
2.1 Ensure Authentication is configuredUnixCIS MongoDB 6 L1 OS Linux v1.1.0
2.1 Ensure Authentication is configuredWindowsCIS MongoDB 5 L1 OS Windows v1.2.0
2.1 Ensure Authentication is configuredWindowsCIS MongoDB 6 L1 OS Windows v1.1.0
2.1 Ensure Authentication is configuredUnixCIS MongoDB 4 L1 OS Linux v1.0.0
2.1 Ensure Authentication is configuredWindowsCIS MongoDB 7 L1 OS Windows v1.0.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionUnixCIS MongoDB 6 L1 OS Linux v1.1.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionWindowsCIS MongoDB 6 L1 OS Windows v1.1.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionUnixCIS MongoDB 5 L1 OS Linux v1.2.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionWindowsCIS MongoDB 4 L1 OS Windows v1.0.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionWindowsCIS MongoDB 3.6 L1 Windows Audit v1.1.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionUnixCIS MongoDB 4 L1 OS Linux v1.0.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionWindowsCIS MongoDB 7 L1 OS Windows v1.0.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionUnixCIS MongoDB 3.6 L1 Unix Audit v1.1.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionWindowsCIS MongoDB 5 L1 OS Windows v1.2.0
2.2 Ensure that MongoDB does not bypass authentication via the localhost exceptionUnixCIS MongoDB 7 L1 OS Linux v1.0.0
2.3.10.1 Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'WindowsCIS Microsoft Windows 11 Stand-alone v2.0.0 L1 + BL
2.3.10.1 Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'WindowsCIS Microsoft Windows 10 Stand-alone v2.0.0 L1 + BL + NG
2.3.10.1 Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'WindowsCIS Microsoft Windows 10 Enterprise v2.0.0 L1 + BL
2.3.10.1 Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'WindowsCIS Microsoft Windows 11 Enterprise v2.0.0 L1
2.3.10.1 Ensure 'Network access: Allow anonymous SID/Name translation' is set to 'Disabled'WindowsCIS Microsoft Windows Server 2008 Domain Controller Level 1 v3.3.1
18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2022 v2.0.0 L1 MS
18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2019 DC L1 v2.0.0
18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2019 Standalone DC L1 vCIS Microsoft Windows Server 2019 Standalone DC L1 v1.0.0
18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2019 MS L1 v2.0.0
18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2022 v2.0.0 L1 DC
18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2016 MS L1 v2.0.0
18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2016 DC L1 v2.0.0
18.10.15.5 Ensure 'Enable OneSettings Auditing' is set to 'Enabled' - EnabledWindowsCIS Microsoft Windows Server 2019 MS Standalone L1 v1.0.0