V-222526
Application Security and Development Security Technical Implementation Guide
Title
The application must use multifactor (e.g., CAC, Alt. Token) authentication for network access to non-privileged accounts.
Description
<VulnDiscussion>To assure accountability and prevent unauthenticated access, non-privileged users must utilize multifactor authentication to prevent potential misuse and compromise of the system. Multifactor authentication uses two or more factors to achieve authentication. Factors include: (i) Something you know (e.g., password/PIN); (ii) Something you have (e.g., cryptographic identification device, CAC/SIPRNet token); or (iii) Something you are (e.g., biometric). A non-privileged account ...
Fix Text (Documentation Requirement)
Configure the application to require CAC or Alt. Token authentication for non-privileged network access to non-privileged accounts.