The container platform must use multifactor authentication for local access to nonprivileged accounts.
Overview
Finding ID
Version
Rule ID
IA Controls
Severity
V-233082
SRG-APP-000152-CTR-000370
SV-233082r981848_rule
Medium
Description
To ensure accountability, prevent unauthenticated access, and prevent misuse of the system, nonprivileged users must utilize multi-factor authentication for local access.
Multifactor authentication is defined as using two or more factors to achieve authentication.
Factors include:
(i) Something a user knows (e.g., password/PIN);
(ii) Something a user has (e.g., cryptographic identification device, token); or
(iii) Something a user is (e.g., biometric).
A nonprivileged account is defined as an information system account with authorizations of a regular or nonprivileged user.
Local access is defined as access to an organizational information system by a user (or process acting on behalf of a user) communicating through a direct connection without the use of a network.