-
Story
-
Resolution: Done
-
Major
-
None
-
None
The organization authorizes network access to [Assignment: organization-defined privileged commands] only for [Assignment: organization-defined compelling operational needs] and documents the rationale for such access in the security plan for the information system.
Supplemental Guidance: Network access is any access across a network connection in lieu of local access (i.e., user being physically present at the device). Related control: AC-17.
References :
https://issues.redhat.com/browse/CMP-116
Work to do :
- Understand the control and how account compass supports the requirement in section a) and b).
- Update control response