STIGhub
STIGs
RMF Controls
Compare
← IA-8 (1) — Identification and Authentication (Non-Organizational Users)
CCI-002009
Definition
Accept Personal Identity Verification-compliant credentials from other federal agencies.
Parent Control
IA-8 (1)
Identification and Authentication (Non-Organizational Users)
Identification and Authentication
Linked STIG Checks (29)
V-279055
CAT I
ColdFusion must be using an enterprise solution for authentication.
Adobe ColdFusion Security Technical Implementation Guide
V-222993
CAT II
Multifactor certificate-based tokens (CAC) must be used when accessing the management interface.
Apache Tomcat Application Server 9 Security Technical Implementation Guide
V-222557
CAT II
The application must accept Personal Identity Verification (PIV) credentials from other federal agencies.
Application Security and Development Security Technical Implementation Guide
V-204806
CAT II
The application server must accept Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.
Application Server Security Requirements Guide
V-272639
CAT II
CylanceON-PREM must be configured with a DOD issued certificate (or another authorizing official [AO]-approved certificate).
Arctic Wolf CylanceON-PREM Security Technical Implementation Guide
V-256844
CAT I
Compliance Guardian must use multifactor authentication for network access to privileged accounts.
AvePoint Compliance Guardian Security Technical Implementation Guide
V-276012
CAT I
Ax-OS must have no local accounts for the user interface.
Axonius Federal Systems Ax-OS Security Technical Implementation Guide
V-233202
CAT II
The container platform must accept Personal Identity Verification (PIV) credentials from other federal agencies.
Container Platform Security Requirements Guide
V-235821
CAT II
SAML integration must be enabled in Docker Enterprise.
Docker Enterprise 2.x Linux/UNIX Security Technical Implementation Guide
V-271034
CAT II
Dragos Platform must accept the DOD CAC or other PKI credential for identity management and personal authentication.
Dragos Platform 2.x Security Technical Implementation Guide
V-278400
CAT II
NGINX must accept Personal Identity Verification (PIV) credentials.
F5 NGINX Security Technical Implementation Guide
V-250335
CAT I
Multifactor authentication for network access to privileged accounts must be used.
IBM WebSphere Liberty Server Security Technical Implementation Guide
V-255865
CAT II
The WebSphere Application Server multifactor authentication for network access to privileged accounts must be used.
IBM WebSphere Traditional V9.x Security Technical Implementation Guide
V-255876
CAT II
The WebSphere Application Server must accept Personal Identity Verification (PIV) credentials from other federal agencies to access the management interface.
IBM WebSphere Traditional V9.x Security Technical Implementation Guide
V-205574
CAT II
The Mainframe Product must accept Personal Identity Verification (PIV) credentials from other federal agencies.
Mainframe Product Security Requirements Guide
V-260909
CAT II
MKE must be configured to integrate with an Enterprise Identity Provider.
Mirantis Kubernetes Engine Security Technical Implementation Guide
V-254111
CAT II
Nutanix AOS must accept Personal Identity Verification (PIV) credentials to access the management interface.
Nutanix AOS 5.20.x Application Security Technical Implementation Guide
V-279434
CAT I
Nutanix AOS must use multifactor authentication for access to privileged and nonprivileged accounts by enabling common access card (CAC) authentication.
Nutanix Acropolis Application Server Security Technical Implementation Guide
V-273204
CAT II
Okta must be configured to accept Personal Identity Verification (PIV) credentials.
Okta Identity as a Service (IDaaS) Security Technical Implementation Guide
V-253539
CAT II
Prisma Cloud Compute must be configured to require local user accounts to use x.509 multifactor authentication.
Palo Alto Networks Prisma Cloud Compute Security Technical Implementation Guide
V-257543
CAT I
OpenShift must use FIPS validated LDAP or OpenIDConnect.
Red Hat OpenShift Container Platform 4.x Security Technical Implementation Guide
V-254093
CAT I
Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts.
SPEC Innovations Innoslate 4.x Security Technical Implementation Guide
V-241005
CAT II
Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
Tanium 7.0 Security Technical Implementation Guide
V-234066
CAT II
Common Access Card (CAC)-based authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
Tanium 7.3 Security Technical Implementation Guide
V-254897
CAT II
Multifactor authentication must be enabled and enforced on the Tanium Server for all access and all accounts.
Tanium 7.x Application on TanOS Security Technical Implementation Guide
V-253800
CAT II
The Tanium application must accept Personal Identity Verification (PIV) credentials from other federal agencies.
Tanium 7.x Security Technical Implementation Guide
V-256324
CAT II
The vCenter Server must require multifactor authentication.
VMware vSphere 7.0 vCenter Security Technical Implementation Guide
V-258910
CAT II
The vCenter Server must require multifactor authentication.
VMware vSphere 8.0 vCenter Security Technical Implementation Guide
V-269574
CAT I
Xylok Security Suite must use a centralized user management solution.
Xylok Security Suite 20.x Security Technical Implementation Guide