IA-11 Re-authentication
Identification and Authentication family. 4 Control Correlation Identifiers map to this control, and 37 STIG rules implement those CCIs.
The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.
It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.
Where these rules come from
| STIG benchmark | Version | Rules mapped to IA-11 |
|---|---|---|
| Microsoft Windows 10 | V3 | 8 |
| Microsoft Windows 11 | V2 | 8 |
| Microsoft Windows Server 2019 | V3 | 6 |
| Microsoft Windows Server 2022 | V2 | 6 |
| Red Hat Enterprise Linux 9 | V2 | 5 |
| Red Hat Enterprise Linux 8 | V2 | 4 |
Control Correlation Identifiers mapped to IA-11
| CCI | Definition | Rev |
|---|---|---|
| CCI-002036 | Defines the circumstances or situations under which users will be required to reauthenticate. | 5, 4 |
| CCI-002037 | The organization defines the circumstances or situations under which devices will be required to reauthenticate. | 4 |
| CCI-002038 | The organization requires users to reauthenticate upon organization-defined circumstances or situations requiring reauthentication. | 5, 4 |
| CCI-002039 | The organization requires devices to reauthenticate upon organization-defined circumstances or situations requiring reauthentication. | 4 |
STIG rules that implement IA-11
| Rule | STIG ID | Severity | Requirement |
|---|---|---|---|
| V-205808 | WN19-CC-000340 | medium | Windows Server 2019 must not save passwords in the Remote Desktop Client. |
| V-205809 | WN19-CC-000360 | medium | Windows Server 2019 Remote Desktop Services must always prompt a client for passwords upon connection. |
| V-205810 | WN19-CC-000520 | medium | Windows Server 2019 Windows Remote Management (WinRM) service must not store RunAs credentials. |
| V-205811 | WN19-SO-000380 | medium | Windows Server 2019 User Account Control approval mode for the built-in Administrator must be enabled. |
| V-205812 | WN19-SO-000410 | medium | Windows Server 2019 User Account Control must automatically deny standard user requests for elevation. |
| V-205813 | WN19-SO-000440 | medium | Windows Server 2019 User Account Control must run all administrators in Admin Approval Mode, enabling UAC. |
| V-220821 | WN10-CC-000145 | medium | Users must be prompted for a password on resume from sleep (on battery). |
| V-220822 | WN10-CC-000150 | medium | The user must be prompted for a password on resume from sleep (plugged in). |
| V-220848 | WN10-CC-000270 | medium | Passwords must not be saved in the Remote Desktop Client. |
| V-220850 | WN10-CC-000280 | medium | Remote Desktop Services must always prompt a client for passwords upon connection. |
| V-220867 | WN10-CC-000355 | medium | The Windows Remote Management (WinRM) service must not store RunAs credentials. |
| V-220944 | WN10-SO-000245 | medium | User Account Control approval mode for the built-in Administrator must be enabled. |
| V-220947 | WN10-SO-000255 | medium | User Account Control must automatically deny elevation requests for standard users. |
| V-220950 | WN10-SO-000270 | medium | User Account Control must run all administrators in Admin Approval Mode, enabling UAC. |
| V-230271 | RHEL-08-010380 | medium | RHEL 8 must require users to provide a password for privilege escalation. |
| V-230272 | RHEL-08-010381 | medium | RHEL 8 must require users to reauthenticate for privilege escalation. |
| V-237643 | RHEL-08-010384 | medium | RHEL 8 must require re-authentication when using the "sudo" command. |
| V-251712 | RHEL-08-010385 | medium | The RHEL 8 operating system must not be configured to bypass password requirements for privilege escalation. |
| V-253380 | WN11-CC-000145 | medium | Users must be prompted for a password on resume from sleep (on battery). |
| V-253381 | WN11-CC-000150 | medium | The user must be prompted for a password on resume from sleep (plugged in). |
| V-253402 | WN11-CC-000270 | medium | Passwords must not be saved in the Remote Desktop Client. |
| V-253404 | WN11-CC-000280 | medium | Remote Desktop Services must always prompt a client for passwords upon connection. |
| V-253420 | WN11-CC-000355 | medium | The Windows Remote Management (WinRM) service must not store RunAs credentials. |
| V-253468 | WN11-SO-000245 | medium | User Account Control approval mode for the built-in Administrator must be enabled. |
| V-253471 | WN11-SO-000255 | medium | User Account Control must automatically deny elevation requests for standard users. |
| V-253474 | WN11-SO-000270 | medium | User Account Control must run all administrators in Admin Approval Mode, enabling UAC. |
| V-254365 | WN22-CC-000340 | medium | Windows Server 2022 must not save passwords in the Remote Desktop Client. |
| V-254367 | WN22-CC-000360 | medium | Windows Server 2022 Remote Desktop Services must always prompt a client for passwords upon connection. |
| V-254383 | WN22-CC-000520 | medium | Windows Server 2022 Windows Remote Management (WinRM) service must not store RunAs credentials. |
| V-254482 | WN22-SO-000380 | medium | Windows Server 2022 User Account Control (UAC) approval mode for the built-in Administrator must be enabled. |
| V-254485 | WN22-SO-000410 | medium | Windows Server 2022 User Account Control (UAC) must automatically deny standard user requests for elevation. |
| V-254488 | WN22-SO-000440 | medium | Windows Server 2022 User Account Control (UAC) must run all administrators in Admin Approval Mode, enabling UAC. |
| V-258084 | RHEL-09-432015 | medium | RHEL 9 must require reauthentication when using the "sudo" command. |
| V-258086 | RHEL-09-432025 | medium | RHEL 9 must require users to reauthenticate for privilege escalation. |
| V-258088 | RHEL-09-432035 | medium | RHEL 9 must restrict the use of the "su" command. |
| V-258106 | RHEL-09-611085 | medium | RHEL 9 must require users to provide a password for privilege escalation. |
| V-258118 | RHEL-09-611145 | medium | RHEL 9 must not be configured to bypass password requirements for privilege escalation. |
Get this as data
The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/IA-11. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.