Skip to main content
CUI

STIG Rule - V-233195

V-233195

SV-233195r961494_rule

CAT II

The container platform must be configured to use multi-factor authentication for user authentication.

From: Container Platform Security Requirements Guide (V2R4)

Description

<VulnDiscussion>Controlling access to the container platform and its components is paramount in having a secure and stable system. Validating users is the first step in controlling the access. Users may be validated by the overall container platform or they may be validated by each component. To standardize and reduce the risks of unauthorized access, the use of multifactor token-based credentials is the preferred method. DoD has mandated the use of the CAC to support identity management and personal authentication for systems covered under HSPD 12, as well as a primary component of layered protection for national security systems.</VulnDiscussion><FalsePositives></FalsePositives><FalseNegatives></FalseNegatives><Documentable>false</Documentable><Mitigations></Mitigations><SeverityOverrideGuidance></SeverityOverrideGuidance><PotentialImpacts></PotentialImpacts><ThirdPartyTools></ThirdPartyTools><MitigationControl></MitigationControl><Responsibility></Responsibility><IAControls></IAControls>

Check Procedure

Review documentation and configuration to ensure the container platform is configured to use an approved DoD multifactor token (CAC) when accessing platform via user interfaces. If multifactor authentication is not configured, this is a finding.

Fix Text

Configure the container platform to accept standard DoD multifactor token-based credentials when users interface with the platform.

CCI Reference

CCI-001953
Created
2026-04-07 20:08:14
Last Updated
2026-04-07 20:08:14
CUI