STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN Client must implement multifactor authentication for network access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.

DISA Rule

SV-207210r984299_rule

Vulnerability Number

V-207210

Group Title

SRG-NET-000145

Rule Version

SRG-NET-000145-VPN-000510

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN Client to implement multifactor authentication for network access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.

Check Contents

Verify the VPN Client implements multifactor authentication for network access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.

If the VPN Client does not implement multifactor authentication for network access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access, this is a finding.

Vulnerability Number

V-207210

Documentable

False

Rule Version

SRG-NET-000145-VPN-000510

Severity Override Guidance

Verify the VPN Client implements multifactor authentication for network access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.

If the VPN Client does not implement multifactor authentication for network access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access, this is a finding.

Check Content Reference

M

Target Key

2920