DoD STIGs – V-32194

Overview:

Title: The DBMS must provide a mechanism to automatically terminate accounts designated as temporary or emergency accounts after an organization defined time period.

Vulnerability ID: V-32194

STIG ID:

IA Controls: None

Severity: medium

Description: Temporary application accounts could ostensibly be used in the event of a vendor support visit where a support representative requires a temporary unique account in order to perform diagnostic testing or conduct some other support related activity. When these types of accounts are created, there is a risk that the temporary account may remain in place and active after the support representative has left.

To address this, in the event temporary application accounts are required, the application must ensure accounts designated as temporary in nature shall automatically terminate these accounts after an organization defined time period. Such a process and capability greatly reduces the risk that accounts will be misused, hijacked, or data compromised.

To address the multitude of policy based access requirements, many application developers choose to integrate their applications with enterprise level authentication/access mechanisms meeting or exceeding access control policy requirements. Such integration allows the application developer to off-load those access control functions and focus on core application features and functionality.

Examples of enterprise level authentication/access mechanisms include, but are not limited to, Active Directory and LDAP.

Temporary database accounts must be automatically terminated after an organization defined time period in order to mitigate the risk of the account being used beyond its original purpose or timeframe.

Check Text: Check DBMS settings, OS settings, and/or enterprise level authentication/access mechanisms settings to determine if the DBMS provides or utilizes a mechanism whereby temporary or emergency accounts can be terminated after an organization defined time period. If the DBMS does not provide or utilize such a mechanism, this is a finding.

Fix Text: Utilize DBMS, or OS software containing mechanisms to terminate temporary database accounts after an organization defined time period.

[divider]

Interpreting V-32194:

Coming Soon!

Return to the DoD STIGs – Database Security Requirements Guide

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.