The organization defines the user actions that can be performed on the information system without identification and authentication.
No STIG checks reference this CCI.