San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

IA-11 Re-authentication

Identification and Authentication family. 4 Control Correlation Identifiers map to this control, and 37 STIG rules implement those CCIs.

0CAT I (high)
37CAT II (medium)
0CAT III (low)
4CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to IA-11
Microsoft Windows 10V38
Microsoft Windows 11V28
Microsoft Windows Server 2019V36
Microsoft Windows Server 2022V26
Red Hat Enterprise Linux 9V25
Red Hat Enterprise Linux 8V24

Control Correlation Identifiers mapped to IA-11

CCIDefinitionRev
CCI-002036Defines the circumstances or situations under which users will be required to reauthenticate.5, 4
CCI-002037The organization defines the circumstances or situations under which devices will be required to reauthenticate.4
CCI-002038The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication.5, 4
CCI-002039The organization requires devices to reauthenticate upon organization-defined circumstances or situations requiring reauthentication.4

STIG rules that implement IA-11

RuleSTIG IDSeverityRequirement
V-205808WN19-CC-000340mediumWindows Server 2019 must not save passwords in the Remote Desktop Client.
V-205809WN19-CC-000360mediumWindows Server 2019 Remote Desktop Services must always prompt a client for passwords upon connection.
V-205810WN19-CC-000520mediumWindows Server 2019 Windows Remote Management (WinRM) service must not store RunAs credentials.
V-205811WN19-SO-000380mediumWindows Server 2019 User Account Control approval mode for the built-in Administrator must be enabled.
V-205812WN19-SO-000410mediumWindows Server 2019 User Account Control must automatically deny standard user requests for elevation.
V-205813WN19-SO-000440mediumWindows Server 2019 User Account Control must run all administrators in Admin Approval Mode, enabling UAC.
V-220821WN10-CC-000145mediumUsers must be prompted for a password on resume from sleep (on battery).
V-220822WN10-CC-000150mediumThe user must be prompted for a password on resume from sleep (plugged in).
V-220848WN10-CC-000270mediumPasswords must not be saved in the Remote Desktop Client.
V-220850WN10-CC-000280mediumRemote Desktop Services must always prompt a client for passwords upon connection.
V-220867WN10-CC-000355mediumThe Windows Remote Management (WinRM) service must not store RunAs credentials.
V-220944WN10-SO-000245mediumUser Account Control approval mode for the built-in Administrator must be enabled.
V-220947WN10-SO-000255mediumUser Account Control must automatically deny elevation requests for standard users.
V-220950WN10-SO-000270mediumUser Account Control must run all administrators in Admin Approval Mode, enabling UAC.
V-230271RHEL-08-010380mediumRHEL 8 must require users to provide a password for privilege escalation.
V-230272RHEL-08-010381mediumRHEL 8 must require users to reauthenticate for privilege escalation.
V-237643RHEL-08-010384mediumRHEL 8 must require re-authentication when using the "sudo" command.
V-251712RHEL-08-010385mediumThe RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation.
V-253380WN11-CC-000145mediumUsers must be prompted for a password on resume from sleep (on battery).
V-253381WN11-CC-000150mediumThe user must be prompted for a password on resume from sleep (plugged in).
V-253402WN11-CC-000270mediumPasswords must not be saved in the Remote Desktop Client.
V-253404WN11-CC-000280mediumRemote Desktop Services must always prompt a client for passwords upon connection.
V-253420WN11-CC-000355mediumThe Windows Remote Management (WinRM) service must not store RunAs credentials.
V-253468WN11-SO-000245mediumUser Account Control approval mode for the built-in Administrator must be enabled.
V-253471WN11-SO-000255mediumUser Account Control must automatically deny elevation requests for standard users.
V-253474WN11-SO-000270mediumUser Account Control must run all administrators in Admin Approval Mode, enabling UAC.
V-254365WN22-CC-000340mediumWindows Server 2022 must not save passwords in the Remote Desktop Client.
V-254367WN22-CC-000360mediumWindows Server 2022 Remote Desktop Services must always prompt a client for passwords upon connection.
V-254383WN22-CC-000520mediumWindows Server 2022 Windows Remote Management (WinRM) service must not store RunAs credentials.
V-254482WN22-SO-000380mediumWindows Server 2022 User Account Control (UAC) approval mode for the built-in Administrator must be enabled.
V-254485WN22-SO-000410mediumWindows Server 2022 User Account Control (UAC) must automatically deny standard user requests for elevation.
V-254488WN22-SO-000440mediumWindows Server 2022 User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC.
V-258084RHEL-09-432015mediumRHEL 9 must require reauthentication when using the "sudo" command.
V-258086RHEL-09-432025mediumRHEL 9 must require users to reauthenticate for privilege escalation.
V-258088RHEL-09-432035mediumRHEL 9 must restrict the use of the "su" command.
V-258106RHEL-09-611085mediumRHEL 9 must require users to provide a password for privilege escalation.
V-258118RHEL-09-611145mediumRHEL 9 must not be configured to bypass password requirements for privilege escalation.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/IA-11. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.