STIGhub
STIGs
RMF Controls
Compare
← AC-6 (5) — Least Privilege
CCI-002227
Definition
Restrict privileged accounts on the system to organization-defined personnel or roles.
Parent Control
AC-6 (5)
Least Privilege
Access Control
Linked STIG Checks (20)
V-224377
CAT II
The BlackBerry UEM server must be configured to have at least one user in the following Administrator roles: Server primary administrator, security configuration administrator, device user group administrator, or auditor.
BlackBerry UEM Security Technical Implementation Guide
V-24342
CAT II
Sign-on to the ESCD Application Console must be restricted to only authorized personnel.
IBM Hardware Management Console (HMC) STIG
V-24344
CAT II
The Distributed Console Access Facility (DCAF) Console must be restricted to only authorized personnel.
IBM Hardware Management Console (HMC) STIG
V-24349
CAT II
Access to the Hardware Management Console must be restricted to only authorized personnel.
IBM Hardware Management Console (HMC) STIG
V-24350
CAT II
Automatic Call Answering to the Hardware Management Console must be disabled.
IBM Hardware Management Console (HMC) STIG
V-256858
CAT II
Sign-on to the ESCD Application Console must be restricted to only authorized personnel.
IBM Hardware Management Console (HMC) Security Technical Implementation Guide
V-256860
CAT II
The Distributed Console Access Facility (DCAF) Console must be restricted to only authorized personnel.
IBM Hardware Management Console (HMC) Security Technical Implementation Guide
V-256871
CAT II
Access to the Hardware Management Console must be restricted to only authorized personnel.
IBM Hardware Management Console (HMC) Security Technical Implementation Guide
V-256873
CAT II
Automatic Call Answering to the Hardware Management Console must be disabled.
IBM Hardware Management Console (HMC) Security Technical Implementation Guide
V-82167
CAT II
The MaaS360 MDM server must be configured to have at least one user in the following Administrator roles: Server primary administrator, security configuration administrator, device user group administrator, auditor.
IBM MaaS360 with Watson v10.x MDM Security Technical Implementation Guide
V-241795
CAT II
The Jamf Pro EMM server must be configured to have at least one user in the following Administrator roles: Server primary administrator, security configuration administrator, device user group administrator, auditor.
Jamf Pro v10.x EMM Security Technical Implementation Guide
V-243444
CAT II
Administrative accounts of all high-value IT resources must be assigned to a specific administrative tier in Active Directory to separate highly privileged administrative accounts from less privileged administrative accounts.
Microsoft Windows PAW Security Technical Implementation Guide
V-91817
CAT II
The MobileIron Core v10 server must be configured to have at least one user in the following Administrator roles: Server primary administrator, security configuration administrator, device user group administrator, auditor.
MobileIron Core v10.x MDM Security Technical Implementation Guide
V-237628
CAT II
The Oracle Linux operating system must use the invoking user's password for privilege escalation when using "sudo".
Oracle Linux 7 Security Technical Implementation Guide
V-237634
CAT II
The Red Hat Enterprise Linux operating system must use the invoking user's password for privilege escalation when using "sudo".
Red Hat Enterprise Linux 7 Security Technical Implementation Guide
V-237642
CAT II
RHEL 8 must use the invoking user's password for privilege escalation when using "sudo".
Red Hat Enterprise Linux 8 Security Technical Implementation Guide
V-237604
CAT II
The SUSE operating system must use the invoking user's password for privilege escalation when using "sudo".
SLES 12 Security Technical Implementation Guide
V-237604
CAT II
The SUSE operating system must use the invoking user's password for privilege escalation when using "sudo".
SUSE Linux Enterprise Server 12 Security Technical Implementation Guide
V-225646
CAT II
The Samsung SDS EMM must be configured to have at least one user in the following Administrator roles: Server primary administrator, security configuration administrator, device user group administrator, auditor.
Samsung SDS EMM Security Technical Implementation Guide
V-221643
CAT II
The Workspace ONE UEM server must be configured to have at least one user in the following Administrator roles: Server primary administrator, security configuration administrator, device user group administrator, or auditor.
VMware Workspace ONE UEM Security Technical Implementation Guide