STIGhubSTIGhub
STIGsSearchCompare

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • Release Notes
  • VPAT
  • DISA STIG Library
STIGs updated 5 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to Network WLAN AP-IG Management Security Technical Implementation Guide

V-243139

CAT II (Medium)

The network device must be configured to authenticate each administrator prior to authorizing privileges based on assignment of group or role.

Rule ID

SV-243139r879594_rule

STIG

Network WLAN AP-IG Management Security Technical Implementation Guide

Version

V7R2

CCIs

CCI-000770

Discussion

To ensure individual accountability and prevent unauthorized access, administrators must be individually identified and authenticated. Individual accountability mandates that each administrator is uniquely identified. A group authenticator is a shared account or some other form of authentication that allows multiple unique individuals to access the network device using a single account. If a device allows or provides for group authenticators, it must individually authenticate administrators prior to implementing group authenticator functionality. Some devices may not have the need to provide a group authenticator; this is considered a matter of device design. Where the device design includes the use of a group authenticator, this requirement will apply. This requirement applies to accounts created and managed on or by the network device.

Check Content

Review the network device configuration and validate that users are authenticated before they are assigned privileges based on the role or group the account is assigned to.

If a user can gain access to network device privileges before they are authenticated, this is a finding.

Fix Text

Configure the network device to authenticate users before assigning privileges to each individual user account based on the role or group the account is assigned to.