CCI|CCI-000765

Title

Implement multifactor authentication for network access to privileged accounts.

Reference Item Details

Category: 2024

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.19 UBTU-24-100650UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.20 UBTU-24-100660UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.30 UBTU-24-100910UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.62 RHEL-09-215075UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.78 UBTU-24-400020UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.79 UBTU-24-400030UnixCIS Ubuntu Linux 24.04 LTS STIG v1.0.0 CAT II
1.102 UBTU-22-612010UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.104 UBTU-22-612020UnixCIS Ubuntu Linux 22.04 LTS STIG v1.0.0 CAT II
1.208 RHEL-09-255035UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.339 RHEL-09-611160UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
1.340 RHEL-09-611165UnixCIS Red Hat Enterprise Linux 9 STIG v1.0.0 CAT II
AIOS-16-014800 - Apple iOS/iPadOS 16 must be configured to disable Auto Unlock of the iPhone by an Apple Watch.MDMAirWatch - DISA Apple iOS/iPadOS 16 v2r1
AIOS-16-014800 - Apple iOS/iPadOS 16 must be configured to disable Auto Unlock of the iPhone by an Apple Watch.MDMMobileIron - DISA Apple iOS/iPadOS 16 v2r1
AIOS-17-014800 - Apple iOS/iPadOS 17 must be configured to disable 'Auto Unlock' of the iPhone by an Apple Watch - Auto Unlock of the iPhone by an Apple Watch.MDMMobileIron - DISA Apple iOS/iPadOS 17 v2r1
AIOS-17-014800 - Apple iOS/iPadOS 17 must be configured to disable 'Auto Unlock' of the iPhone by an Apple Watch - Auto Unlock of the iPhone by an Apple Watch.MDMAirWatch - DISA Apple iOS/iPadOS 17 v2r1
AIOS-18-014800 - Apple iOS/iPadOS 18 must be configured to disable 'Auto Unlock' of the iPhone by an Apple Watch - Auto Unlock of the iPhone by an Apple Watch.MDMAirWatch - DISA Apple iOS/iPadOS 18 v1r4
AIOS-18-014800 - Apple iOS/iPadOS 18 must be configured to disable 'Auto Unlock' of the iPhone by an Apple Watch - Auto Unlock of the iPhone by an Apple Watch.MDMMobileIron - DISA Apple iOS/iPadOS 18 v1r4
AIX7-00-003200 - The AIX operating system must use Multi Factor Authentication.UnixDISA STIG AIX 7.x v3r1
ALMA-09-033240 - AlmaLinux OS 9 SSHD must accept public key authentication.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-033790 - AlmaLinux OS 9 must enable certificate based smart card authentication.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-034010 - AlmaLinux OS 9 must have the openssl-pkcs11 package installed.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
ALMA-09-034340 - AlmaLinux OS 9 must use the CAC smart card driver.UnixDISA CloudLinux AlmaLinux OS 9 STIG v1r2
AOSX-14-003020 - The macOS system must use multifactor authentication for local and network access to privileged and non-privileged accounts - ChallengeResponseAuthenticationUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-003020 - The macOS system must use multifactor authentication for local and network access to privileged and non-privileged accounts - enforceSmartCardUnixDISA STIG Apple Mac OSX 10.14 v2r6
AOSX-14-003020 - The macOS system must use multifactor authentication for local and network access to privileged and non-privileged accounts - PasswordAuthenticationUnixDISA STIG Apple Mac OSX 10.14 v2r6
APPL-14-001150 The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003020 The macOS system must enforce smart card authentication.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003030 The macOS system must allow smart card authentication.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003050 The macOS system must enforce multifactor authentication for logon.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003051 The macOS system must enforce multifactor authentication for the su command.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-14-003052 The macOS system must enforce multifactor authentication for privilege escalation through the sudo command.UnixDISA Apple macOS 14 (Sonoma) STIG v2r3
APPL-15-001150 - The macOS system must disable password authentication for SSH.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4
APPL-15-003020 - The macOS system must enforce smart card authentication.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4
APPL-15-003030 - The macOS system must allow smart card authentication.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4
APPL-15-003050 - The macOS system must enforce multifactor authentication for login.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4
APPL-15-003051 - The macOS system must enforce multifactor authentication for the su command.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4
APPL-15-003052 - The macOS system must enforce multifactor authentication for privilege escalation through the sudo command.UnixDISA Apple macOS 15 (Sequoia) STIG v1r4
Big Sur - Enforce multifactor authentication for network access to privileged accountsUnixNIST macOS Big Sur v1.4.0 - All Profiles
Catalina - Enforce multifactor authentication for network access to privileged accountsUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 Low
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 Moderate
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 High
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-171
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r4 High
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 Low
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - 800-53r5 Moderate
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - All Profiles
Catalina - Enforce Smartcard AuthenticationUnixNIST macOS Catalina v1.5.0 - CNSSI 1253
DKER-EE-002180 - SAML integration must be enabled in Docker Enterprise.UnixDISA STIG Docker Enterprise 2.x Linux/Unix UCP v2r2
ESXI-80-000052 - The ESXi host Secure Shell (SSH) daemon must ignore .rhosts files.UnixDISA VMware vSphere 8.0 ESXi STIG v2r3