Change V-73217 to require manual review #37
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The STIG author's intent is to confirm whether the administrative accounts are not the same as the individual's everyday non-privileged account. The individual's everyday non-privileged account may not necessarily exist on the server or under the users group. Hence, it is difficult to automate concisely. Currently the describe block only confirms whether the accounts/groups in the local administrators group match the supplied inputs array. It does not address the STIG author's requirements. Hence, the describe block should be converted to a skip, requiring manual review, similar to method used for V-73225.
describe "A manual review is required to verify that each user with administrative privileges has a separate account for user duties and one for privileged duties." do
skip "A manual review is required to verify that each user with administrative privileges has a separate account for user duties and one for privileged duties."
end