CCI|CCI-002039

Title

The organization requires devices to reauthenticate upon organization-defined circumstances or situations requiring reauthentication.

Reference Item Details

Category: 2013

Audit Items

View all Reference Audit Items

NamePluginAudit Name
AMLS-L2-000150 - The Arista Multilayer Switch must re-authenticate 802.1X connected devices every hour - dot1x timeout reauth-period 3600AristaDISA STIG Arista MLS DCS-7000 Series L2S v1r2
AMLS-L2-000150 - The Arista Multilayer Switch must re-authenticate 802.1X connected devices every hour - logging level DOT1X informationalAristaDISA STIG Arista MLS DCS-7000 Series L2S v1r2
Big Sur - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Moderate
Big Sur - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 Low
Big Sur - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Big Sur v1.4.0 - 800-53r5 High
Big Sur - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Big Sur v1.4.0 - All Profiles
BIND-9X-001100 - The BIND 9.x server implementation must uniquely identify and authenticate the other DNS server before responding to a server-to-server transaction, zone transfer and/or dynamic update request using cryptographically based bidirectional authentication to protect the integrity of the information in transit - allow-transfer noneUnixDISA BIND 9.x STIG v2r2
BIND-9X-001100 - The BIND 9.x server implementation must uniquely identify and authenticate the other DNS server before responding to a server-to-server transaction, zone transfer and/or dynamic update request using cryptographically based bidirectional authentication to protect the integrity of the information in transit - master allow-transferUnixDISA BIND 9.x STIG v2r2
BIND-9X-001100 - The BIND 9.x server implementation must uniquely identify and authenticate the other DNS server before responding to a server-to-server transaction, zone transfer and/or dynamic update request using cryptographically based bidirectional authentication to protect the integrity of the information in transit - secondary keysUnixDISA BIND 9.x STIG v2r2
Catalina - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Catalina v1.5.0 - All Profiles
Monterey - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Monterey v1.0.0 - 800-53r5 High
Monterey - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Monterey v1.0.0 - All Profiles
Monterey - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Monterey v1.0.0 - 800-53r5 Low
Monterey - Require Devices to Reauthenticate when Changing AuthenticatorsUnixNIST macOS Monterey v1.0.0 - 800-53r5 Moderate
WDNS-IA-000001 - The Windows 2012 DNS Server must require devices to re-authenticate for each dynamic update request connection attempt.WindowsDISA Microsoft Windows 2012 Server DNS STIG v2r5