CSCv6|5.8

Title

Administrators should be required to access a system using a fully logged and non-administrative account.

Description

Administrators should be required to access a system using a fully logged and non-administrative account. Then, once logged on to the machine without administrative privileges, the administrator should transition to administrative privileges using tools such as Sudo on Linux/UNIX, RunAs on Windows, and other similar facilities for other types of systems.

Reference Item Details

Category: Controlled Use of Administrative Privileges

Family: System

Audit Items

View all Reference Audit Items

NamePluginAudit Name
1.1.2.44 Set 'Audit Policy: Logon-Logoff: Special Logon' to 'Success'WindowsCIS Windows 8 L1 v1.0.0
4.1 Ensure sudo is configured correctlyUnixCIS PostgreSQL 9.6 OS v1.0.0
4.1 Ensure sudo is configured correctlyUnixCIS PostgreSQL 11 OS v1.0.0
4.1 Ensure sudo is configured correctlyUnixCIS PostgreSQL 9.5 OS v1.1.0
4.1 Ensure sudo is configured correctlyUnixCIS PostgreSQL 10 OS v1.0.0
4.1 Ensure sudo is configured correctly - /etc/sudoersUnixCIS PostgreSQL 14 OS v1.0.0
4.1 Ensure sudo is configured correctly - /etc/sudoersUnixCIS PostgreSQL 13 OS v1.0.0
4.1 Ensure sudo is configured correctly - /etc/sudoersUnixCIS PostgreSQL 12 OS v1.0.0
4.1 Ensure sudo is configured correctly - /etc/sudoers.d/postgresUnixCIS PostgreSQL 14 OS v1.0.0
4.1 Ensure sudo is configured correctly - /etc/sudoers.d/postgresUnixCIS PostgreSQL 13 OS v1.0.0
4.1 Ensure sudo is configured correctly - /etc/sudoers.d/postgresUnixCIS PostgreSQL 12 OS v1.0.0
5.2.8 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0
5.2.8 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0
5.2.8 Ensure SSH root login is disabledUnixCIS Amazon Linux v2.1.0 L1
5.2.10 Ensure SSH root login is disabledUnixCIS Debian 8 Server L1 v2.0.2
5.2.10 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 18.04 LXD Container L1 v1.0.0
5.2.10 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 18.04 LXD Host L1 Workstation v1.0.0
5.2.10 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 18.04 LXD Host L1 Server v1.0.0
5.2.10 Ensure SSH root login is disabledUnixCIS Distribution Independent Linux Workstation L1 v2.0.0
5.2.10 Ensure SSH root login is disabledUnixCIS Debian 8 Workstation L1 v2.0.2
5.2.10 Ensure SSH root login is disabledUnixCIS Distribution Independent Linux Server L1 v2.0.0
5.2.14 Ensure SSH access is limitedUnixCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0
5.2.14 Ensure SSH access is limitedUnixCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0
5.2.14 Ensure SSH access is limitedUnixCIS Amazon Linux v2.1.0 L1
5.2.18 Ensure SSH access is limitedUnixCIS Debian 8 Workstation L1 v2.0.2
5.2.18 Ensure SSH access is limitedUnixCIS Debian 8 Server L1 v2.0.2
5.2.18 Ensure SSH access is limitedUnixCIS Distribution Independent Linux Server L1 v2.0.0
5.2.18 Ensure SSH access is limitedUnixCIS Distribution Independent Linux Workstation L1 v2.0.0
5.3.10 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 18.04 LTS Server L1 v2.1.0
5.3.10 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 20.04 LTS Workstation L1 v1.1.0
5.3.10 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 20.04 LTS Server L1 v1.1.0
5.3.10 Ensure SSH root login is disabledUnixCIS Ubuntu Linux 18.04 LTS Workstation L1 v2.1.0
5.3.11 Ensure SSH root login is disabledUnixCIS Oracle Linux 6 Server L1 v2.0.0
5.3.11 Ensure SSH root login is disabledUnixCIS Red Hat 6 Server L1 v3.0.0
17.5.5 (L1) Ensure 'Audit Special Logon' is set to include 'Success'WindowsCIS Microsoft Windows 8.1 v2.4.0 L1
17.5.5 (L1) Ensure 'Audit Special Logon' is set to include 'Success'WindowsCIS Microsoft Windows 8.1 v2.4.0 L1 Bitlocker
17.5.5 Ensure 'Audit Special Logon' is set to include 'Success'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
17.5.5 Ensure 'Audit Special Logon' is set to include 'Success'WindowsCIS Windows 7 Workstation Level 1 v3.2.0
17.5.6 Ensure 'Audit Special Logon' is set to include 'Success'WindowsCIS Microsoft Windows 11 Enterprise v1.0.0 L1 + NG
17.5.6 Ensure 'Audit Special Logon' is set to include 'Success'WindowsCIS Microsoft Windows 11 Enterprise v1.0.0 L1 + BL
17.5.6 Ensure 'Audit Special Logon' is set to include 'Success'WindowsCIS Microsoft Windows 11 Enterprise v1.0.0 L1
17.5.6 Ensure 'Audit Special Logon' is set to include 'Success'WindowsCIS Microsoft Windows 11 Enterprise v1.0.0 L1 + BL + NG
18.3.1 (L1) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'WindowsCIS Microsoft Windows 8.1 v2.4.0 L1 Bitlocker
18.3.1 (L1) Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'WindowsCIS Microsoft Windows 8.1 v2.4.0 L1
18.3.1 Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v1.0.0 L1 + NG
18.3.1 Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v1.0.0 L1 + BL + NG
18.3.1 Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 v3.2.0
18.3.1 Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v1.0.0 L1 + BL
18.3.1 Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'WindowsCIS Windows 7 Workstation Level 1 + Bitlocker v3.2.0
18.3.1 Ensure 'Apply UAC restrictions to local accounts on network logons' is set to 'Enabled'WindowsCIS Microsoft Windows 11 Enterprise v1.0.0 L1