HYCU Protege Security Technical Implementation Guide

Overview

VersionDateFinding Count (55)Downloads
12024-10-29CAT I (High): 11CAT II (Medium): 44CAT III (Low): 0
STIG Description
This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via email to the following address: disa.stig_spt@mail.mil.
ClassifiedPublicSensitive
I - Mission Critical ClassifiedI - Mission Critical PublicI - Mission Critical Sensitive
II - Mission Support ClassifiedII - Mission Support PublicII - Mission Support Sensitive
III - Administrative ClassifiedIII - Administrative PublicIII - Administrative Sensitive

Findings - MAC II - Mission Support Public

Finding IDSeverityTitleDescription
V-268216
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured to synchronize internal information system clocks using redundant authoritative time sources.The loss of connectivity to a particular authoritative time source will result in the loss of time synchronization (free-run mode) and increasingly in...
V-268217
LOWMEDIUMHIGH
The HYCU virtual appliance must not have any default manufacturer passwords when deployed.Virtual machines not protected with strong password schemes provide the opportunity for anyone to crack the password and gain access to the device, wh...
V-268219
LOWMEDIUMHIGH
The HYCU virtual appliance must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of al...
V-268223
LOWMEDIUMHIGH
If the HYCU virtual appliance uses role-based access control, it must enforce organization-defined role-based access control policies over defined subjects and objects.Organizations can create specific roles based on job functions and the authorizations (i.e., privileges) to perform needed operations on organizationa...
V-268225
LOWMEDIUMHIGH
The HYCU virtual appliance must enforce approved authorizations for controlling the flow of management information within the appliance based on information flow control policies.A mechanism to detect and prevent unauthorized communication flow must be configured or provided as part of the system design. If management informati...
V-268226
LOWMEDIUMHIGH
The HYCU virtual appliance must audit the execution of privileged functions.Misuse of privileged functions, either intentionally or unintentionally by authorized users, or by unauthorized external entities that have compromise...
V-268227
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured to enforce the limit of three consecutive invalid login attempts, after which time it must block any login attempt for 15 minutes.By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, ...
V-268228
LOWMEDIUMHIGH
The HYCU virtual appliance must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device.Display of the DOD-approved use notification before granting access to the network device ensures privacy and security notification verbiage used is c...
V-268229
LOWMEDIUMHIGH
The HYCU virtual appliance must retain the Standard Mandatory DOD Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log in for further access.The banner must be acknowledged by the administrator prior to the device allowing the administrator access to the network device. This provides assura...
V-268231
LOWMEDIUMHIGH
The HYCU virtual appliance must automatically audit account creation.Upon gaining access to a network device, an attacker will often first attempt to create a persistent method of reestablishing access. One way to accom...
V-268232
LOWMEDIUMHIGH
The HYCU virtual appliance must automatically audit account modification.Since the accounts in the network device are privileged or system-level accounts, account management is vital to the security of the network device. A...
V-268233
LOWMEDIUMHIGH
The HYCU virtual appliance must automatically audit account disabling actions.Account management ensures access to the network device is being controlled in a secure manner by granting access to only authorized personnel. Auditi...
V-268234
LOWMEDIUMHIGH
The HYCU virtual appliance must automatically audit account removal actions.Account management, as a whole, ensures access to the network device is being controlled in a secure manner by granting access to only authorized pers...
V-268238
LOWMEDIUMHIGH
The HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to access privileges occur.Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlat...
V-268239
LOWMEDIUMHIGH
The HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to modify administrator privileges occur.Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlat...
V-268240
LOWMEDIUMHIGH
The HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to delete administrator privileges occur.Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlat...
V-268241
LOWMEDIUMHIGH
The HYCU virtual appliance must generate audit records when successful/unsuccessful login attempts occur.Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlat...
V-268242
LOWMEDIUMHIGH
The HYCU virtual appliance must generate audit records for privileged activities or other system-level access.Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlat...
V-268244
LOWMEDIUMHIGH
The HYCU virtual appliance must generate log records for a locally developed list of auditable events.Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlat...
V-268245
LOWMEDIUMHIGH
The HYCU virtual appliance must produce audit records containing information to establish when events occurred, where events occurred, the source of the event, the outcome of the event, and identity of any individual or process associated with the event.It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, and by whom it was done to...
V-268246
LOWMEDIUMHIGH
The HYCU virtual appliance must generate audit records containing the full-text recording of privileged commands.Reconstruction of harmful events or forensic analysis is not possible if audit records do not contain enough information. Organizations consider lim...
V-268247
LOWMEDIUMHIGH
The HYCU virtual appliance must produce audit log records containing sufficient information to establish what type of event occurred.It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, and by whom it was done to...
V-268248
LOWMEDIUMHIGH
The HYCU virtual appliance must initiate session auditing upon startup.It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, and by whom it was done to...
V-268249
LOWMEDIUMHIGH
The HYCU virtual appliance must automatically audit account enabling actions.It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, and by whom it was done to...
V-268250
LOWMEDIUMHIGH
The HYCU virtual appliance must generate audit records showing starting and ending time for administrator access to the system.It is essential for security personnel to know what is being done, what was attempted, where it was done, when it was done, and by whom it was done to...
V-268251
LOWMEDIUMHIGH
The HYCU virtual appliance must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.To ensure network devices have a sufficient storage capacity in which to write the audit logs, they must be able to allocate audit record storage capa...
V-268252
LOWMEDIUMHIGH
The HYCU virtual appliance must support organizational requirements to conduct backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner.Information system backup is a critical step in maintaining data assurance and availability. Information system and security-related documentation con...
V-268253
LOWMEDIUMHIGH
The HYCU virtual appliance must off-load audit records onto a different system or media than the system being audited.Information system backup is a critical step in maintaining data assurance and availability. Information system and security-related documentation con...
V-268254
LOWMEDIUMHIGH
The HYCU virtual appliance must generate an immediate real-time alert of all audit failure events requiring real-time alerts.It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without a real-time aler...
V-268255
LOWMEDIUMHIGH
The HYCU virtual appliance must protect audit information from unauthorized deletion.Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully audit information system ac...
V-268256
LOWMEDIUMHIGH
The HYCU virtual appliance must protect audit tools from unauthorized access, modification, and deletion.Protecting audit data also includes identifying and protecting the tools used to view and manipulate log data. Therefore, protecting audit tools is ne...
V-268258
LOWMEDIUMHIGH
The HYCU virtual appliance must obtain its public key certificates from an appropriate certificate policy through an approved service provider.For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agenci...
V-268260
LOWMEDIUMHIGH
The HYCU virtual appliance must implement replay-resistant authentication mechanisms for network access to privileged accounts.A replay attack may enable an unauthorized user to gain access to the application. Authentication sessions between the authenticator and the applicati...
V-268262
LOWMEDIUMHIGH
The HYCU virtual appliance must enforce password complexity by requiring that at least one uppercase character be used.Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measur...
V-268263
LOWMEDIUMHIGH
The HYCU virtual appliance must enforce password complexity by requiring that at least one lowercase character be used.Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measur...
V-268264
LOWMEDIUMHIGH
The HYCU virtual appliance must enforce password complexity by requiring that at least one numeric character be used.Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measur...
V-268265
LOWMEDIUMHIGH
The HYCU virtual appliance must enforce password complexity by requiring that at least one special character be used.Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measur...
V-268266
LOWMEDIUMHIGH
The HYCU virtual appliance must enforce a minimum 15-character password length.Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password ...
V-268267
LOWMEDIUMHIGH
The HYCU virtual appliance must require that when a password is changed, the characters are changed in at least eight of the positions within the password.If the application allows the user to consecutively reuse extensive portions of passwords, this increases the chances of password compromise by increa...
V-268274
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.Authentication for administrative (privileged level) access to the device is required at all times. An account can be created on the device's local da...
V-268282
LOWMEDIUMHIGH
The HYCU virtual appliance must audit the enforcement actions used to restrict access associated with changes to the device.Without auditing the enforcement of access restrictions against changes to the device configuration, it will be difficult to identify attempted attack...
V-268283
LOWMEDIUMHIGH
The HYCU virtual appliance must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.Changes to any software components can have significant effects on the overall security of the network device. Verifying software components have been...
V-268296
LOWMEDIUMHIGH
The HYCU virtual appliance must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).Security flaws with software are discovered daily. Vendors are constantly updating and patching their products to address newly discovered security vu...
V-268302
LOWMEDIUMHIGH
The HYCU virtual appliance must generate unique session identifiers using a FIPS 140-2 approved random number generator.Sequentially generated session IDs can be easily guessed by an attacker. Employing the concept of randomness in the generation of unique session ident...
V-268222
LOWMEDIUMHIGH
The HYCU virtual appliance must enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level in accordance with applicable policy for the device.To mitigate the risk of unauthorized access to sensitive information by entities that have been issued certificates by DOD-approved PKIs, all DOD syst...
V-268235
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured to use DOD-approved online certificate status protocol (OCSP) responders or certificate revocation lists (CRLs) to validate certificates used for PKI-based authentication.Once issued by a DOD certificate authority (CA), public key infrastructure (PKI) certificates are typically valid for three years or shorter within th...
V-268236
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured to use at least two authentication servers for authenticating users prior to granting administration access.Centralized management of authentication settings increases the security of remote and nonlocal access methods. This control is particularly important...
V-268237
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins.MFA is when two or more factors are used to confirm the identity of an individual who is requesting access to digital information resources. Valid fac...
V-268257
LOWMEDIUMHIGH
The HYCU virtual appliance must be running a release that is currently supported by the vendor.Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated with recent vulnerabilit...
V-268259
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.To prevent unauthorized connection of devices, unauthorized transfer of information, or unauthorized tunneling (i.e., embedding of data types within d...
V-268269
LOWMEDIUMHIGH
The HYCU virtual appliance must use FIPS 140-2-approved algorithms for authentication to a cryptographic module.Unapproved mechanisms that are used for authentication to the cryptographic module are not validated and therefore cannot be relied upon to provide co...
V-268270
LOWMEDIUMHIGH
The HYCU virtual appliance must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.Unapproved mechanisms that are used for authentication to the cryptographic module are not verified and therefore cannot be relied on to provide confi...
V-268271
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured to implement cryptographic mechanisms using a FIPS 140-2-approved algorithm to protect the confidentiality of remote maintenance sessions.This requires the use of secure protocols instead of their unsecured counterparts, such as SSH instead of telnet, SCP instead of FTP, and HTTPS instea...
V-268301
LOWMEDIUMHIGH
The HYCU virtual appliance must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.Terminating an idle session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management se...
V-268303
LOWMEDIUMHIGH
The HYCU virtual appliance must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).The aggregation of log data kept on a syslog server can be used to detect attacks and trigger an alert to the appropriate security personnel. The stor...