San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active

IA-2 Identification and Authentication (Organizational Users)

Identification and Authentication family. 33 Control Correlation Identifiers map to this control, and 39 STIG rules implement those CCIs.

1CAT I (high)
38CAT II (medium)
0CAT III (low)
33CCIs
What this page is built from, and what it is not.

The mapping below is derived from 8 DISA STIG benchmarks (Google Chrome Current Windows, Kubernetes, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9) covering 2,030 rules, joined to 5,137 Control Correlation Identifiers.

It is not the complete STIG library. A control showing no rules here means no rule in these benchmarks maps to it, not that no STIG covers it. CCI to control mappings are published by DISA and reflect both Revision 4 and Revision 5 of NIST SP 800-53; where the two revisions disagree, both are shown. This page reports what the source data says and nothing further. It is not a compliance determination.

Where these rules come from

STIG benchmarkVersionRules mapped to IA-2
Red Hat Enterprise Linux 9V213
Microsoft Windows Server 2019V38
Microsoft Windows Server 2022V28
Red Hat Enterprise Linux 8V26
Microsoft Windows 10V32
Microsoft Windows 11V22

Control Correlation Identifiers mapped to IA-2

CCIDefinitionRev
CCI-000764Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.5, 4
CCI-000765Implement multifactor authentication for access to privileged accounts.5, 4
CCI-000766Implement multifactor authentication for access to non-privileged accounts.5, 4
CCI-000767The information system implements multifactor authentication for local access to privileged accounts.4
CCI-000768The information system implements multifactor authentication for local access to non-privileged accounts.4
CCI-000770The organization requires individuals to be authenticated with an individual authenticator when a group authenticator is employed.4
CCI-001935The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access to privileged accounts.4
CCI-001936The information system implements multifactor authentication for network access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access.4
CCI-001937The device used in the information system implementation of multifactor authentication for network access to privileged accounts meets organization-defined strength of mechanism requirements.4
CCI-001938The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access to non-privileged accounts.4
CCI-001939The information system implements multifactor authentication for network access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.4
CCI-001940The device used in the information system implementation of multifactor authentication for network access to non-privileged accounts meets organization-defined strength of mechanism requirements.4
CCI-001941Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.5, 4
CCI-001942The information system implements replay-resistant authentication mechanisms for network access to non-privileged accounts.4
CCI-001943Defines the system accounts for which single sign-on capability will be provided.5, 4
CCI-001944Defines the system services for which single sign-on capability will be provided.5, 4
CCI-001945Provide a single sign-on capability for organization-defined system accounts.5, 4
CCI-001946Provide a single sign-on capability for organization-defined system services.5, 4
CCI-001947The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access and is to provide one factor of a multifactor authentication for remote access to privileged accounts.4
CCI-001948The information system implements multifactor authentication for remote access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access.4
CCI-001949The device used in the information system implementation of multifactor authentication for remote access to privileged accounts meets organization-defined strength of mechanism requirements.4
CCI-001950The organization defines the strength of mechanism requirements for the device that is separate from the system gaining access and is to provide one factor of a multifactor authentication for remote access to non-privileged accounts.4
CCI-001951The information system implements multifactor authentication for remote access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.4
CCI-001952The device used in the information system implementation of multifactor authentication for remote access to non-privileged accounts meets organization-defined strength of mechanism requirements.4
CCI-001953Accept Personal Identity Verification-compliant credentials.5, 4
CCI-001954Electronically verify Personal Identity Verification-compliant credentials.5, 4
CCI-001955Defines the out-of-band authentication to be implemented under organization-defined conditions.5, 4
CCI-001956Defines the conditions for implementing organization-defined out-of-band authentication.5, 4
CCI-001957Implement organization-defined out-of-band authentication mechanisms under organization-defined conditions.5, 4
CCI-004045Require users to be individually authenticated before granting access to the shared accounts or resources.5
CCI-004046Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.5
CCI-004047Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that the device meets organization-defined strength of mechanism requirements.5
CCI-004048Defines the strength of mechanism requirements for implementing multi-factor authentication.5

STIG rules that implement IA-2

RuleSTIG IDSeverityRequirement
V-205699WN19-00-000070mediumWindows Server 2019 shared user accounts must not be permitted.
V-205700WN19-00-000200mediumWindows Server 2019 accounts must require passwords.
V-205701WN19-DC-000310mediumWindows Server 2019 Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication.
V-205702WN19-DC-000020mediumWindows Server 2019 Kerberos user logon restrictions must be enforced.
V-205703WN19-DC-000030mediumWindows Server 2019 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less.
V-205704WN19-DC-000040mediumWindows Server 2019 Kerberos user ticket lifetime must be limited to 10 hours or less.
V-205705WN19-DC-000050mediumWindows Server 2019 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less.
V-205706WN19-DC-000060mediumWindows Server 2019 computer clock synchronization tolerance must be limited to five minutes or less.
V-220908WN10-SO-000005mediumThe built-in administrator account must be disabled.
V-220946WN10-SO-000251mediumWindows 10 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.
V-230273RHEL-08-010390mediumRHEL 8 must have the packages required for multifactor authentication installed.
V-230274RHEL-08-010400mediumRHEL 8 must implement certificate status checking for multifactor authentication.
V-230275RHEL-08-010410mediumRHEL 8 must accept Personal Identity Verification (PIV) credentials.
V-230296RHEL-08-010550mediumRHEL 8 must not permit direct logons to the root account using remote access via SSH.
V-230371RHEL-08-020240mediumRHEL 8 duplicate User IDs (UIDs) must not exist for interactive users.
V-230372RHEL-08-020250mediumRHEL 8 must implement smart card logon for multifactor authentication for access to interactive accounts.
V-253432WN11-SO-000005mediumThe built-in administrator account must be disabled.
V-253470WN11-SO-000251mediumWindows 11 must use multifactor authentication for local and network access to privileged and nonprivileged accounts.
V-254244WN22-00-000070mediumWindows Server 2022 shared user accounts must not be permitted.
V-254257WN22-00-000200mediumWindows Server 2022 accounts must require passwords.
V-254386WN22-DC-000020mediumWindows Server 2022 Kerberos user logon restrictions must be enforced.
V-254387WN22-DC-000030mediumWindows Server 2022 Kerberos service ticket maximum lifetime must be limited to 600 minutes or less.
V-254388WN22-DC-000040mediumWindows Server 2022 Kerberos user ticket lifetime must be limited to 10 hours or less.
V-254389WN22-DC-000050mediumWindows Server 2022 Kerberos policy user ticket renewal maximum lifetime must be limited to seven days or less.
V-254390WN22-DC-000060mediumWindows Server 2022 computer clock synchronization tolerance must be limited to five minutes or less.
V-254415WN22-DC-000310mediumWindows Server 2022 Active Directory user accounts, including administrators, must be configured to require the use of a Common Access Card (CAC), Personal Identity Verification (PIV)-compliant hardware token, or Alternate Logon Token (ALT) for user authentication.
V-257838RHEL-09-215075mediumRHEL 9 must have the openssl-pkcs11 package installed.
V-257983RHEL-09-255035mediumRHEL 9 SSHD must accept public key authentication.
V-257984RHEL-09-255040highRHEL 9 SSHD must not allow blank passwords.
V-257985RHEL-09-255045mediumRHEL 9 must not permit direct logons to the root account using remote access via SSH.
V-258045RHEL-09-411030mediumRHEL 9 duplicate User IDs (UIDs) must not exist for interactive users.
V-258048RHEL-09-411045mediumAll RHEL 9 interactive users must have a primary group that exists.
V-258061RHEL-09-411110mediumRHEL 9 groups must have unique Group ID (GID).
V-258121RHEL-09-611160mediumRHEL 9 must use the common access card (CAC) smart card driver.
V-258122RHEL-09-611165mediumRHEL 9 must enable certificate based smart card authentication.
V-258123RHEL-09-611170mediumRHEL 9 must implement certificate status checking for multifactor authentication.
V-258124RHEL-09-611175mediumRHEL 9 must have the pcsc-lite package installed.
V-258125RHEL-09-611180mediumThe pcscd service on RHEL 9 must be active.
V-258126RHEL-09-611185mediumRHEL 9 must have the opensc package installed.

Get this as data

The same mapping is served as JSON, no key required: /api/v1/stig-nist/control/IA-2. The interactive version of the full cube is the STIG to NIST mapper, and the endpoint is documented on the compliance API page.