{
    "control": "IA-2",
    "title": "Identification and Authentication (Organizational Users)",
    "ccis": [
        {
            "cci": "CCI-000764",
            "definition": "Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users."
        },
        {
            "cci": "CCI-000765",
            "definition": "Implement multifactor authentication for access to privileged accounts."
        },
        {
            "cci": "CCI-000766",
            "definition": "Implement multifactor authentication for access to non-privileged accounts."
        },
        {
            "cci": "CCI-000767",
            "definition": "The information system implements multifactor authentication for local access to privileged accounts."
        },
        {
            "cci": "CCI-000768",
            "definition": "The information system implements multifactor authentication for local access to non-privileged accounts."
        },
        {
            "cci": "CCI-000770",
            "definition": "The organization requires individuals to be authenticated with an individual authenticator when a group authenticator is employed."
        },
        {
            "cci": "CCI-001935",
            "definition": "The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access to privileged accounts."
        },
        {
            "cci": "CCI-001936",
            "definition": "The information system implements multifactor authentication for network access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access."
        },
        {
            "cci": "CCI-001937",
            "definition": "The device used in the information system implementation of multifactor authentication for network access to privileged accounts meets organization-defined strength of mechanism requirements."
        },
        {
            "cci": "CCI-001938",
            "definition": "The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access to non-privileged accounts."
        },
        {
            "cci": "CCI-001939",
            "definition": "The information system implements multifactor authentication for network access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access."
        },
        {
            "cci": "CCI-001940",
            "definition": "The device used in the information system implementation of multifactor authentication for network access to non-privileged accounts meets organization-defined strength of mechanism requirements."
        },
        {
            "cci": "CCI-001941",
            "definition": "Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts."
        },
        {
            "cci": "CCI-001942",
            "definition": "The information system implements replay-resistant authentication mechanisms for network access to non-privileged accounts."
        },
        {
            "cci": "CCI-001943",
            "definition": "Defines the system accounts for which single sign-on capability will be provided."
        },
        {
            "cci": "CCI-001944",
            "definition": "Defines the system services for which single sign-on capability will be provided."
        },
        {
            "cci": "CCI-001945",
            "definition": "Provide a single sign-on capability for organization-defined system accounts."
        },
        {
            "cci": "CCI-001946",
            "definition": "Provide a single sign-on capability for organization-defined system services."
        },
        {
            "cci": "CCI-001947",
            "definition": "The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access and is to provide one factor of a multifactor authentication for remote access to privileged accounts."
        },
        {
            "cci": "CCI-001948",
            "definition": "The information system implements multifactor authentication for remote access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access."
        },
        {
            "cci": "CCI-001949",
            "definition": "The device used in the information system implementation of multifactor authentication for remote access to privileged accounts meets organization-defined strength of mechanism requirements."
        },
        {
            "cci": "CCI-001950",
            "definition": "The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access and is to provide one factor of a multifactor authentication for remote access to non-privileged accounts."
        },
        {
            "cci": "CCI-001951",
            "definition": "The information system implements multifactor authentication for remote access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access."
        },
        {
            "cci": "CCI-001952",
            "definition": "The device used in the information system implementation of multifactor authentication for remote access to non-privileged accounts meets organization-defined strength of mechanism requirements."
        },
        {
            "cci": "CCI-001953",
            "definition": "Accept Personal Identity Verification-compliant credentials."
        },
        {
            "cci": "CCI-001954",
            "definition": "Electronically verify Personal Identity Verification-compliant credentials."
        },
        {
            "cci": "CCI-001955",
            "definition": "Defines the out-of-band authentication to be implemented under organization-defined conditions."
        },
        {
            "cci": "CCI-001956",
            "definition": "Defines the conditions for implementing organization-defined out-of-band authentication."
        },
        {
            "cci": "CCI-001957",
            "definition": "Implement organization-defined out-of-band authentication mechanisms under organization-defined conditions."
        }
    ],
    "rules_mapped": 39,
    "rules": [
        {
            "rule": "V-220908",
            "stig_id": "WN10-SO-000005",
            "title": "The built-in administrator account must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-220946",
            "stig_id": "WN10-SO-000251",
            "title": "Windows 10 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 10",
            "ccis": [
                "CCI-000765"
            ]
        },
        {
            "rule": "V-253432",
            "stig_id": "WN11-SO-000005",
            "title": "The built-in administrator account must be disabled.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-253470",
            "stig_id": "WN11-SO-000251",
            "title": "Windows 11 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.",
            "severity": "medium",
            "benchmark": "Microsoft Windows 11",
            "ccis": [
                "CCI-000765"
            ]
        },
        {
            "rule": "V-205699",
            "stig_id": "WN19-00-000070",
            "title": "Windows Server 2019 shared user accounts must not be permitted.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-205700",
            "stig_id": "WN19-00-000200",
            "title": "Windows Server 2019 accounts must require passwords.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-205701",
            "stig_id": "WN19-DC-000310",
            "title": "Windows Server 2019 Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-000767",
                "CCI-000768",
                "CCI-001948"
            ]
        },
        {
            "rule": "V-205702",
            "stig_id": "WN19-DC-000020",
            "title": "Windows Server 2019 Kerberos user logon restrictions must be enforced.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001942"
            ]
        },
        {
            "rule": "V-205703",
            "stig_id": "WN19-DC-000030",
            "title": "Windows Server 2019 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-205704",
            "stig_id": "WN19-DC-000040",
            "title": "Windows Server 2019 Kerberos user ticket lifetime must be limited to 10 hours or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-205705",
            "stig_id": "WN19-DC-000050",
            "title": "Windows Server 2019 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-205706",
            "stig_id": "WN19-DC-000060",
            "title": "Windows Server 2019 computer clock synchronization tolerance must be limited to five minutes or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2019",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-254244",
            "stig_id": "WN22-00-000070",
            "title": "Windows Server 2022 shared user accounts must not be permitted.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-254257",
            "stig_id": "WN22-00-000200",
            "title": "Windows Server 2022 accounts must require passwords.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-254386",
            "stig_id": "WN22-DC-000020",
            "title": "Windows Server 2022 Kerberos user logon restrictions must be enforced.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-254387",
            "stig_id": "WN22-DC-000030",
            "title": "Windows Server 2022 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-254388",
            "stig_id": "WN22-DC-000040",
            "title": "Windows Server 2022 Kerberos user ticket lifetime must be limited to 10 hours or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-254389",
            "stig_id": "WN22-DC-000050",
            "title": "Windows Server 2022 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-254390",
            "stig_id": "WN22-DC-000060",
            "title": "Windows Server 2022 computer clock synchronization tolerance must be limited to five minutes or less.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-001941",
                "CCI-001942"
            ]
        },
        {
            "rule": "V-254415",
            "stig_id": "WN22-DC-000310",
            "title": "Windows Server 2022 Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication.",
            "severity": "medium",
            "benchmark": "Microsoft Windows Server 2022",
            "ccis": [
                "CCI-000767",
                "CCI-000768",
                "CCI-000776",
                "CCI-001948"
            ]
        },
        {
            "rule": "V-230273",
            "stig_id": "RHEL-08-010390",
            "title": "RHEL 8 must have the packages required for multifactor authentication installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001948",
                "CCI-004046"
            ]
        },
        {
            "rule": "V-230274",
            "stig_id": "RHEL-08-010400",
            "title": "RHEL 8 must implement certificate status checking for multifactor authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001948",
                "CCI-004046"
            ]
        },
        {
            "rule": "V-230275",
            "stig_id": "RHEL-08-010410",
            "title": "RHEL 8 must accept Personal Identity Verification (PIV) credentials.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-001953"
            ]
        },
        {
            "rule": "V-230296",
            "stig_id": "RHEL-08-010550",
            "title": "RHEL 8 must not permit direct logons to the root account using remote access via SSH.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000770",
                "CCI-004045"
            ]
        },
        {
            "rule": "V-230371",
            "stig_id": "RHEL-08-020240",
            "title": "RHEL 8 duplicate User IDs (UIDs) must not exist for interactive users.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-230372",
            "stig_id": "RHEL-08-020250",
            "title": "RHEL 8 must implement smart card logon for multifactor authentication for access to interactive accounts.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 8",
            "ccis": [
                "CCI-000765"
            ]
        },
        {
            "rule": "V-257838",
            "stig_id": "RHEL-09-215075",
            "title": "RHEL 9 must have the openssl-pkcs11 package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000765",
                "CCI-001948",
                "CCI-001953",
                "CCI-001954",
                "CCI-004046"
            ]
        },
        {
            "rule": "V-257983",
            "stig_id": "RHEL-09-255035",
            "title": "RHEL 9 SSHD must accept public key authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000765",
                "CCI-000766",
                "CCI-000767",
                "CCI-000768"
            ]
        },
        {
            "rule": "V-257984",
            "stig_id": "RHEL-09-255040",
            "title": "RHEL 9 SSHD must not allow blank passwords.",
            "severity": "high",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000766"
            ]
        },
        {
            "rule": "V-257985",
            "stig_id": "RHEL-09-255045",
            "title": "RHEL 9 must not permit direct logons to the root account using remote access via SSH.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000770",
                "CCI-004045"
            ]
        },
        {
            "rule": "V-258045",
            "stig_id": "RHEL-09-411030",
            "title": "RHEL 9 duplicate User IDs (UIDs) must not exist for interactive users.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000135",
                "CCI-000764",
                "CCI-000804"
            ]
        },
        {
            "rule": "V-258048",
            "stig_id": "RHEL-09-411045",
            "title": "All RHEL 9 interactive users must have a primary group that exists.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-258061",
            "stig_id": "RHEL-09-411110",
            "title": "RHEL 9 groups must have unique Group ID (GID).",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000764"
            ]
        },
        {
            "rule": "V-258121",
            "stig_id": "RHEL-09-611160",
            "title": "RHEL 9 must use the common access card (CAC) smart card driver.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000764",
                "CCI-000765",
                "CCI-000766",
                "CCI-000767",
                "CCI-000768",
                "CCI-000770",
                "CCI-001941",
                "CCI-001942",
                "CCI-004045"
            ]
        },
        {
            "rule": "V-258122",
            "stig_id": "RHEL-09-611165",
            "title": "RHEL 9 must enable certificate based smart card authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-000765",
                "CCI-001948",
                "CCI-004046",
                "CCI-004047"
            ]
        },
        {
            "rule": "V-258123",
            "stig_id": "RHEL-09-611170",
            "title": "RHEL 9 must implement certificate status checking for multifactor authentication.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001948",
                "CCI-001954",
                "CCI-004046"
            ]
        },
        {
            "rule": "V-258124",
            "stig_id": "RHEL-09-611175",
            "title": "RHEL 9 must have the pcsc-lite package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001948",
                "CCI-004046"
            ]
        },
        {
            "rule": "V-258125",
            "stig_id": "RHEL-09-611180",
            "title": "The pcscd service on RHEL 9 must be active.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001948",
                "CCI-004046"
            ]
        },
        {
            "rule": "V-258126",
            "stig_id": "RHEL-09-611185",
            "title": "RHEL 9 must have the opensc package installed.",
            "severity": "medium",
            "benchmark": "Red Hat Enterprise Linux 9",
            "ccis": [
                "CCI-001948",
                "CCI-001953",
                "CCI-004046"
            ]
        }
    ]
}