STIGQter STIGQter: STIG Summary: ISEC7 Sphere Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The ISEC7 SPHERE must configure the timeout for the console to be 15 minutes or less.

DISA Rule

SV-224774r1013835_rule

Vulnerability Number

V-224774

Group Title

SRG-APP-000516

Rule Version

ISEC-06-002520

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Set the session timeout to the correct value of 15 minutes or less.

Check Contents

Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Validate the session timeout has been set to the correct value.

Alternatively, allow the console to sit for 15 minutes and confirm that the user is prompted to log in once again when attempting to navigate to a new screen.

If the SPHERE Console timeout has not been set for 15 minutes or less, this is a finding.

Vulnerability Number

V-224774

Documentable

False

Rule Version

ISEC-06-002520

Severity Override Guidance

Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Validate the session timeout has been set to the correct value.

Alternatively, allow the console to sit for 15 minutes and confirm that the user is prompted to log in once again when attempting to navigate to a new screen.

If the SPHERE Console timeout has not been set for 15 minutes or less, this is a finding.

Check Content Reference

M

Target Key

4200