STIGQter STIGQter: STIG Summary: ISEC7 EMM Suite v6.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 23 Aug 2019:

When using PKI-based authentication for user access, the ISEC7 EMM Suite must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.

DISA Rule

SV-106499r1_rule

Vulnerability Number

V-97395

Group Title

SRG-APP-000175

Rule Version

ISEC-06-000780

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Login to the server(s) hosting the ISEC7 EMM Suite application.
Open the Microsoft Management Console and add the Local Computer Certificates snap-in.
Open the Trusted Root Certification Authorities >> Certificates.
Install the DoD Root PKI Certificates Authorities to the server.

Check Contents

Login to the server(s) hosting the ISEC7 EMM Suite application.
Open the Microsoft Management Console and add the Local Computer Certificates snap-in.
Open the Trusted Root Certification Authorities >> Certificates.
Verify the DoD Root PKI Certificates Authorities have been added to the server.

If the DoD Root PKI Certificates Authorities have not been added to the server, this is a finding.

Vulnerability Number

V-97395

Documentable

False

Rule Version

ISEC-06-000780

Severity Override Guidance

Login to the server(s) hosting the ISEC7 EMM Suite application.
Open the Microsoft Management Console and add the Local Computer Certificates snap-in.
Open the Trusted Root Certification Authorities >> Certificates.
Verify the DoD Root PKI Certificates Authorities have been added to the server.

If the DoD Root PKI Certificates Authorities have not been added to the server, this is a finding.

Check Content Reference

M

Target Key

3503

Comments