Add requirement to review exemptions to smart card login. #131

Closed
opened 2026-01-19 18:29:20 +00:00 by michael · 2 comments
Owner

Originally created by @akegerreis on GitHub.

Originally assigned to: @brodjieski on GitHub.

If a site is using smart card login but is also allowing unmapped users, the exemption list should be documented with the ISSM.

Originally created by @akegerreis on GitHub. Originally assigned to: @brodjieski on GitHub. If a site is using smart card login but is also allowing unmapped users, the exemption list should be documented with the ISSM.
Author
Owner

@robertgendler commented on GitHub:

@akegerreis do you have a suggestion on how this should appear in the project?

A note in supplemental where unmapped users is talked about?
A separate rule?

@robertgendler commented on GitHub: @akegerreis do you have a suggestion on how this should appear in the project? A note in supplemental where unmapped users is talked about? A separate rule?
Author
Owner

@akegerreis commented on GitHub:

@robertgendler we have this slated to go into the supplemental for our April release of the STIG.

@akegerreis commented on GitHub: @robertgendler we have this slated to go into the supplemental for our April release of the STIG.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: usnistgov/macos_security#131