Skip to main content
CUI

Documentation - V-222412

V-222412

Application Security and Development Security Technical Implementation Guide

CAT II

Title

Unnecessary application accounts must be disabled, or deleted.

Description

<VulnDiscussion>Test or demonstration accounts are sometimes created during the application installation process. This creates a security risk as these accounts often remain after the initial installation process and can be used to gain unauthorized access to the application. Applications must be designed and configured to disable or delete any unnecessary accounts that may be created. Care must be taken to ensure valid accounts used for valid application operations are not disabled or deleted...

Fix Text (Documentation Requirement)

Design the application so unessential user accounts are not created during installation. Disable or delete all unnecessary application user accounts.

Documentation Status

Cancel
CUI