STIGQter STIGQter: STIG Summary: Symantec ProxySG NDM Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Jan 2020:

Symantec ProxySG must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirements.

DISA Rule

SV-104543r1_rule

Vulnerability Number

V-94713

Group Title

SRG-APP-000190-NDM-000267

Rule Version

SYMP-NM-000310

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the device management session inactivity timeouts to "10" minutes.

1. Log on to the Web Management Console.
2. Click Configuration >> Authentication >> Console Access >> Console Account.
3. Set "Enforce Web auto-logout" and "Enforce CLI auto-logout" to "10" minutes.

Check Contents

If there is a documented and validated mission requirement which allows the inactivity period to exceed "10" minutes, this is not a finding.

Verify the device management session inactivity timeouts are set to "10" minutes.

1. Log on to the Web Management Console.
2. Click Configuration >> Authentication >> Console Access >> Console Account.
3. Confirm that the "Enforce Web auto-logout" and "Enforce CLI auto-logout" options are set to "10" minutes.

If Symantec ProxySG is not configured to terminate the management session after "10" minutes of inactivity, this is a finding.

Vulnerability Number

V-94713

Documentable

False

Rule Version

SYMP-NM-000310

Severity Override Guidance

If there is a documented and validated mission requirement which allows the inactivity period to exceed "10" minutes, this is not a finding.

Verify the device management session inactivity timeouts are set to "10" minutes.

1. Log on to the Web Management Console.
2. Click Configuration >> Authentication >> Console Access >> Console Account.
3. Confirm that the "Enforce Web auto-logout" and "Enforce CLI auto-logout" options are set to "10" minutes.

If Symantec ProxySG is not configured to terminate the management session after "10" minutes of inactivity, this is a finding.

Check Content Reference

M

Target Key

3517

Comments