{
    "control": "IA-11",
    "title": "Re-authentication",
    "ccis": [
        {
            "cci": "CCI-002036",
            "definition": "Defines the circumstances or situations under which users will be required to reauthenticate."
        },
        {
            "cci": "CCI-002037",
            "definition": "The organization defines the circumstances or situations under which devices will be required to reauthenticate."
        },
        {
            "cci": "CCI-002038",
            "definition": "The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication."
        },
        {
            "cci": "CCI-002039",
            "definition": "The organization requires devices to reauthenticate upon organization-defined circumstances or situations requiring reauthentication."
        }
    ],
    "rules_mapped": 37,
    "rules": [
        {
            "rule": "V-220821",
            "stig_id": "WN10-CC-000145",
            "title": "Users must be prompted for a password on resume from sleep (on battery).",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-220822",
            "stig_id": "WN10-CC-000150",
            "title": "The user must be prompted for a password on resume from sleep (plugged in).",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-220848",
            "stig_id": "WN10-CC-000270",
            "title": "Passwords must not be saved in the Remote Desktop Client.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-220850",
            "stig_id": "WN10-CC-000280",
            "title": "Remote Desktop Services must always prompt a client for passwords upon connection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-220867",
            "stig_id": "WN10-CC-000355",
            "title": "The Windows Remote Management (WinRM) service must not store RunAs credentials.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-220944",
            "stig_id": "WN10-SO-000245",
            "title": "User Account Control approval mode for the built-in Administrator must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-220947",
            "stig_id": "WN10-SO-000255",
            "title": "User Account Control must automatically deny elevation requests for standard users.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-220950",
            "stig_id": "WN10-SO-000270",
            "title": "User Account Control must run all administrators in Admin Approval Mode, enabling UAC.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-253380",
            "stig_id": "WN11-CC-000145",
            "title": "Users must be prompted for a password on resume from sleep (on battery).",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-253381",
            "stig_id": "WN11-CC-000150",
            "title": "The user must be prompted for a password on resume from sleep (plugged in).",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-253402",
            "stig_id": "WN11-CC-000270",
            "title": "Passwords must not be saved in the Remote Desktop Client.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-253404",
            "stig_id": "WN11-CC-000280",
            "title": "Remote Desktop Services must always prompt a client for passwords upon connection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-253420",
            "stig_id": "WN11-CC-000355",
            "title": "The Windows Remote Management (WinRM) service must not store RunAs credentials.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-253468",
            "stig_id": "WN11-SO-000245",
            "title": "User Account Control approval mode for the built-in Administrator must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-253471",
            "stig_id": "WN11-SO-000255",
            "title": "User Account Control must automatically deny elevation requests for standard users.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-253474",
            "stig_id": "WN11-SO-000270",
            "title": "User Account Control must run all administrators in Admin Approval Mode, enabling UAC.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-205808",
            "stig_id": "WN19-CC-000340",
            "title": "Windows Server 2019 must not save passwords in the Remote Desktop Client.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-205809",
            "stig_id": "WN19-CC-000360",
            "title": "Windows Server 2019 Remote Desktop Services must always prompt a client for passwords upon connection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-205810",
            "stig_id": "WN19-CC-000520",
            "title": "Windows Server 2019 Windows Remote Management (WinRM) service must not store RunAs credentials.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-205811",
            "stig_id": "WN19-SO-000380",
            "title": "Windows Server 2019 User Account Control approval mode for the built-in Administrator must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-205812",
            "stig_id": "WN19-SO-000410",
            "title": "Windows Server 2019 User Account Control must automatically deny standard user requests for elevation.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-205813",
            "stig_id": "WN19-SO-000440",
            "title": "Windows Server 2019 User Account Control must run all administrators in Admin Approval Mode, enabling UAC.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-254365",
            "stig_id": "WN22-CC-000340",
            "title": "Windows Server 2022 must not save passwords in the Remote Desktop Client.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-254367",
            "stig_id": "WN22-CC-000360",
            "title": "Windows Server 2022 Remote Desktop Services must always prompt a client for passwords upon connection.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-254383",
            "stig_id": "WN22-CC-000520",
            "title": "Windows Server 2022 Windows Remote Management (WinRM) service must not store RunAs credentials.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-254482",
            "stig_id": "WN22-SO-000380",
            "title": "Windows Server 2022 User Account Control (UAC) approval mode for the built-in Administrator must be enabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-254485",
            "stig_id": "WN22-SO-000410",
            "title": "Windows Server 2022 User Account Control (UAC) must automatically deny standard user requests for elevation.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-254488",
            "stig_id": "WN22-SO-000440",
            "title": "Windows Server 2022 User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-002038"
            ]
        },
        {
            "rule": "V-230271",
            "stig_id": "RHEL-08-010380",
            "title": "RHEL 8 must require users to provide a password for privilege escalation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002038",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-230272",
            "stig_id": "RHEL-08-010381",
            "title": "RHEL 8 must require users to reauthenticate for privilege escalation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002038",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-237643",
            "stig_id": "RHEL-08-010384",
            "title": "RHEL 8 must require re-authentication when using the \"sudo\" command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002038",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-251712",
            "stig_id": "RHEL-08-010385",
            "title": "The RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-002038",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-258084",
            "stig_id": "RHEL-09-432015",
            "title": "RHEL 9 must require reauthentication when using the \"sudo\" command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002038",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-258086",
            "stig_id": "RHEL-09-432025",
            "title": "RHEL 9 must require users to reauthenticate for privilege escalation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002038",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-258088",
            "stig_id": "RHEL-09-432035",
            "title": "RHEL 9 must restrict the use of the \"su\" command.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002038",
                "CCI-002165",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-258106",
            "stig_id": "RHEL-09-611085",
            "title": "RHEL 9 must require users to provide a password for privilege escalation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002038",
                "CCI-004895"
            ]
        },
        {
            "rule": "V-258118",
            "stig_id": "RHEL-09-611145",
            "title": "RHEL 9 must not be configured to bypass password requirements for privilege escalation.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-002038",
                "CCI-004895"
            ]
        }
    ]
}