TCMax must accept personal identity verification (PIV) credentials.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-281377TCMA-09-000165SV-281377r1186158_ruleCCI-001953medium
Description
Using PIV credentials facilitates standardization and reduces the risk of unauthorized access. DOD has mandated using the common access card (CAC) to support identity management and personal authentication for systems covered under HSPD 12, as well as a primary component of layered protection for national security systems. Satisfies: SRG-APP-000391, SRG-APP-000392
STIGDate
Soaring Software Solutions TCMax 9.x Security Technical Implementation Guide2026-03-05

Details

Check Text (C-281377r1186158_chk)

Using an account of appropriate privileges to access TCMax, go to Settings >> Options. Under "Login and User Options", if "Link Windows IDs to TCMax user accounts" is not checked, this is a finding. If "Close TCMax when Windows user account is locked" is not checked, this is a finding.

Fix Text (F-85843r1186157_fix)

1. Using an account of appropriate privileges to access TCMax, go to Settings >> Options. 2. Under "Login and User Options", check the box for "Link Windows IDs to TCMax user accounts". 3. Check the box for "Close TCMax when Windows user account is locked". 4. Click "Save".