{
    "control": "AC-2",
    "title": "Account Management",
    "ccis": [
        {
            "cci": "CCI-000008",
            "definition": "The organization establishes conditions for group membership."
        },
        {
            "cci": "CCI-000010",
            "definition": "Require approvals by organization-defined personnel or roles for requests to create accounts."
        },
        {
            "cci": "CCI-000011",
            "definition": "Create, enable, modify, disable, and remove system accounts in accordance with organization-defined procedures."
        },
        {
            "cci": "CCI-000012",
            "definition": "Review accounts for compliance with account management requirements per organization-defined frequency."
        },
        {
            "cci": "CCI-000015",
            "definition": "Support the management of system accounts using organization-defined automated mechanisms."
        },
        {
            "cci": "CCI-000016",
            "definition": "Automatically remove or disable temporary and emergency accounts after an organization-defined time-period for each type of account."
        },
        {
            "cci": "CCI-000017",
            "definition": "Disable accounts when the accounts have been inactive for the organization-defined time-period."
        },
        {
            "cci": "CCI-000018",
            "definition": "Automatically audit account creation actions."
        },
        {
            "cci": "CCI-000019",
            "definition": "Require that users log out in accordance with the organization-defined time-period of expected inactivity or description of when to log out."
        },
        {
            "cci": "CCI-000217",
            "definition": "Defines a time period after which inactive accounts are automatically disabled."
        },
        {
            "cci": "CCI-001358",
            "definition": "Establish privileged user accounts in accordance with a role-based access scheme; or an attribute-based access scheme."
        },
        {
            "cci": "CCI-001360",
            "definition": "Monitor privileged role assignments."
        },
        {
            "cci": "CCI-001361",
            "definition": "Defines a time period after which temporary accounts are automatically terminated."
        },
        {
            "cci": "CCI-001365",
            "definition": "Defines a time period after which emergency accounts are automatically terminated."
        },
        {
            "cci": "CCI-001403",
            "definition": "Automatically audit account modification actions."
        },
        {
            "cci": "CCI-001404",
            "definition": "Automatically audit account disabling actions."
        },
        {
            "cci": "CCI-001405",
            "definition": "Automatically audit account removal actions."
        },
        {
            "cci": "CCI-001406",
            "definition": "Defines a time period of expected inactivity when users are required to log out."
        },
        {
            "cci": "CCI-001407",
            "definition": "Administer privileged user accounts in accordance with a role-based access scheme; or an attribute-based access scheme."
        },
        {
            "cci": "CCI-001547",
            "definition": "Defines the frequency on which it will review information system accounts for compliance with account management requirements."
        },
        {
            "cci": "CCI-001682",
            "definition": "Automatically remove or disable emergency accounts after an organization-defined time period for each type of account."
        },
        {
            "cci": "CCI-001683",
            "definition": "The information system notifies organization-defined personnel or roles for account creation actions."
        },
        {
            "cci": "CCI-001684",
            "definition": "The information system notifies organization-defined personnel or roles for account modification actions."
        },
        {
            "cci": "CCI-001685",
            "definition": "The information system notifies organization-defined personnel or roles for account disabling actions."
        },
        {
            "cci": "CCI-001686",
            "definition": "The information system notifies organization-defined personnel or roles for account removal actions."
        },
        {
            "cci": "CCI-002110",
            "definition": "The organization defines the information system account types that support the organizational missions/business functions."
        },
        {
            "cci": "CCI-002111",
            "definition": "The organization identifies and selects the organization-defined information system account types of information system accounts which support organizational missions/business functions."
        },
        {
            "cci": "CCI-002112",
            "definition": "Assign account managers."
        },
        {
            "cci": "CCI-002113",
            "definition": "The organization establishes conditions for role membership."
        },
        {
            "cci": "CCI-002114",
            "definition": "The organization specifies authorized users of the information system for each account."
        },
        {
            "cci": "CCI-002115",
            "definition": "Specify authorized users of the system."
        },
        {
            "cci": "CCI-002116",
            "definition": "Specify authorized users of the group."
        },
        {
            "cci": "CCI-002117",
            "definition": "Specify authorized users of the role membership."
        },
        {
            "cci": "CCI-002118",
            "definition": "Specify authorized access authorizations (i.e., privileges) for each account."
        },
        {
            "cci": "CCI-002119",
            "definition": "Specify organization-attributes (as required) for each account on the system."
        },
        {
            "cci": "CCI-002120",
            "definition": "Defines the personnel or roles authorized to approve the creation of accounts."
        },
        {
            "cci": "CCI-002121",
            "definition": "Defines the procedures to be employed when creating, enabling, modifying, disabling, and removing information system accounts."
        },
        {
            "cci": "CCI-002122",
            "definition": "Monitor the use of accounts."
        },
        {
            "cci": "CCI-002123",
            "definition": "Notify account managers and organization-defined personnel or roles within an organization-defined time-period when accounts are no longer required."
        },
        {
            "cci": "CCI-002124",
            "definition": "Notify account managers and organization-defined personnel or roles within an organization-defined time-period when users are terminated or transferred."
        },
        {
            "cci": "CCI-002125",
            "definition": "Notify account managers and organization-defined personnel or roles within an organization-defined time-period when system usage or need-to-know changes for an individual."
        },
        {
            "cci": "CCI-002126",
            "definition": "Authorize access to the system based on a valid access authorization."
        },
        {
            "cci": "CCI-002127",
            "definition": "Authorize access to the system based on intended system usage."
        },
        {
            "cci": "CCI-002128",
            "definition": "Authorize access to the system based on organization-defined attributes (as required)."
        },
        {
            "cci": "CCI-002129",
            "definition": "Establish and implement a process for changing shared or group account authenticators (if deployed) when individuals are removed from the group."
        },
        {
            "cci": "CCI-002130",
            "definition": "Automatically audit account enabling actions."
        },
        {
            "cci": "CCI-002131",
            "definition": "The organization defines the personnel or roles to be notified on account creation, modification, enabling, disabling, and removal actions."
        },
        {
            "cci": "CCI-002132",
            "definition": "The information system notifies organization-defined personnel or roles for account enabling actions."
        },
        {
            "cci": "CCI-002133",
            "definition": "Defines other conditions when users are required to log out."
        },
        {
            "cci": "CCI-002134",
            "definition": "Defines a list of dynamic privilege management capabilities to be implemented."
        },
        {
            "cci": "CCI-002135",
            "definition": "Implement the organization-defined list of dynamic privilege management capabilities."
        },
        {
            "cci": "CCI-002136",
            "definition": "The organization defines the actions to be taken when privileged role assignments are no longer appropriate."
        },
        {
            "cci": "CCI-002137",
            "definition": "Revoke access when privileged role or attribute assignments are no longer appropriate."
        },
        {
            "cci": "CCI-002138",
            "definition": "Defines the system accounts that can be dynamically created."
        },
        {
            "cci": "CCI-002139",
            "definition": "Create organization-defined system accounts dynamically."
        },
        {
            "cci": "CCI-002140",
            "definition": "Defines the conditions for establishing shared/group accounts."
        },
        {
            "cci": "CCI-002141",
            "definition": "Only permit the use of shared and group accounts that meet organization-defined conditions for establishing shared and group accounts."
        },
        {
            "cci": "CCI-002142",
            "definition": "The information system terminates shared/group account credentials when members leave the group."
        },
        {
            "cci": "CCI-002143",
            "definition": "Defines the circumstances and/or usage conditions that are to be enforced for organization-defined information system accounts."
        },
        {
            "cci": "CCI-002144",
            "definition": "Defines the system accounts that are to be subject to the enforcement of organization-defined circumstances and/or usage conditions."
        },
        {
            "cci": "CCI-002145",
            "definition": "Enforce organization-defined circumstances and/or usage conditions for organization-defined system accounts."
        },
        {
            "cci": "CCI-002146",
            "definition": "Defines atypical usage for which the system accounts are to be monitored."
        },
        {
            "cci": "CCI-002147",
            "definition": "Monitor system accounts for organization-defined atypical usage."
        },
        {
            "cci": "CCI-002148",
            "definition": "Defines the personnel or roles to whom atypical usage of system accounts are to be reported."
        },
        {
            "cci": "CCI-002149",
            "definition": "Report atypical usage of system accounts to organization-defined personnel or roles."
        },
        {
            "cci": "CCI-002150",
            "definition": "Defines the time period within which the accounts of users posing a significant risk are to be disabled after discovery of the risk."
        },
        {
            "cci": "CCI-002151",
            "definition": "Disable accounts of individuals within an organization-defined time-period of discovery of organization-defined significant risk."
        }
    ],
    "rules_mapped": 31,
    "rules": [
        {
            "rule": "V-242381",
            "stig_id": "CNTR-K8-000220",
            "title": "The Kubernetes Controller Manager must create unique service accounts for each work payload.",
            "severity": "high",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000015"
            ]
        },
        {
            "rule": "V-242403",
            "stig_id": "CNTR-K8-000700",
            "title": "Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event.",
            "severity": "medium",
            "benchmark": "Kubernetes",
            "ccis": [
                "CCI-000018",
                "CCI-000130",
                "CCI-000131",
                "CCI-000132",
                "CCI-000133",
                "CCI-000134",
                "CCI-000135",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001487",
                "CCI-002264"
            ]
        },
        {
            "rule": "V-220750",
            "stig_id": "WN10-AU-000030",
            "title": "The system must be configured to audit Account Management - Security Group Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220751",
            "stig_id": "WN10-AU-000035",
            "title": "The system must be configured to audit Account Management - User Account Management failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-220752",
            "stig_id": "WN10-AU-000040",
            "title": "The system must be configured to audit Account Management - User Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002234"
            ]
        },
        {
            "rule": "V-253310",
            "stig_id": "WN11-AU-000040",
            "title": "The system must be configured to audit Account Management - User Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-001403"
            ]
        },
        {
            "rule": "V-205624",
            "stig_id": "WN19-00-000300",
            "title": "Windows Server 2019 must automatically remove or disable temporary user accounts after 72 hours.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000016"
            ]
        },
        {
            "rule": "V-205625",
            "stig_id": "WN19-AU-000100",
            "title": "Windows Server 2019 must be configured to audit Account Management - Security Group Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-205626",
            "stig_id": "WN19-AU-000110",
            "title": "Windows Server 2019 must be configured to audit Account Management - User Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-205627",
            "stig_id": "WN19-AU-000120",
            "title": "Windows Server 2019 must be configured to audit Account Management - User Account Management failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-205628",
            "stig_id": "WN19-DC-000230",
            "title": "Windows Server 2019 must be configured to audit Account Management - Computer Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-205710",
            "stig_id": "WN19-00-000310",
            "title": "Windows Server 2019 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001682"
            ]
        },
        {
            "rule": "V-205730",
            "stig_id": "WN19-AU-000160",
            "title": "Windows Server 2019 must be configured to audit Logon/Logoff - Account Lockout failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000172",
                "CCI-001404"
            ]
        },
        {
            "rule": "V-254267",
            "stig_id": "WN22-00-000300",
            "title": "Windows Server 2022 must automatically remove or disable temporary user accounts after 72 hours.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000016"
            ]
        },
        {
            "rule": "V-254268",
            "stig_id": "WN22-00-000310",
            "title": "Windows Server 2022 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001682"
            ]
        },
        {
            "rule": "V-254303",
            "stig_id": "WN22-AU-000100",
            "title": "Windows Server 2022 must be configured to audit Account Management - Security Group Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-254304",
            "stig_id": "WN22-AU-000110",
            "title": "Windows Server 2022 must be configured to audit Account Management - User Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-254305",
            "stig_id": "WN22-AU-000120",
            "title": "Windows Server 2022 must be configured to audit Account Management - User Account Management failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-254309",
            "stig_id": "WN22-AU-000160",
            "title": "Windows Server 2022 must be configured to audit Logon/Logoff - Account Lockout failures.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000172",
                "CCI-001404"
            ]
        },
        {
            "rule": "V-254407",
            "stig_id": "WN22-DC-000230",
            "title": "Windows Server 2022 must be configured to audit Account Management - Computer Account Management successes.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000018",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130"
            ]
        },
        {
            "rule": "V-230331",
            "stig_id": "RHEL-08-020000",
            "title": "RHEL 8 temporary user accounts must be provisioned with an expiration time of 72 hours or less.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000016"
            ]
        },
        {
            "rule": "V-230374",
            "stig_id": "RHEL-08-020270",
            "title": "RHEL 8 must automatically expire temporary accounts within 72 hours.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001682"
            ]
        },
        {
            "rule": "V-258047",
            "stig_id": "RHEL-09-411040",
            "title": "RHEL 9 must automatically expire temporary accounts within 72 hours.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000016",
                "CCI-001682"
            ]
        },
        {
            "rule": "V-258217",
            "stig_id": "RHEL-09-654215",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258218",
            "stig_id": "RHEL-09-654220",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/sudoers.d/ directory.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258219",
            "stig_id": "RHEL-09-654225",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/group.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258220",
            "stig_id": "RHEL-09-654230",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/gshadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258221",
            "stig_id": "RHEL-09-654235",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/opasswd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258222",
            "stig_id": "RHEL-09-654240",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/passwd.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-001683",
                "CCI-001684",
                "CCI-001685",
                "CCI-001686",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-258223",
            "stig_id": "RHEL-09-654245",
            "title": "RHEL 9 must generate audit records for all account creations, modifications, disabling, and termination events that affect /etc/shadow.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015",
                "CCI-000018",
                "CCI-000130",
                "CCI-000135",
                "CCI-000169",
                "CCI-000172",
                "CCI-001403",
                "CCI-001404",
                "CCI-001405",
                "CCI-002130",
                "CCI-002132",
                "CCI-002884"
            ]
        },
        {
            "rule": "V-272488",
            "stig_id": "RHEL-09-215101",
            "title": "RHEL 9 must have the Postfix package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000015"
            ]
        }
    ]
}