STIGQter STIGQter: STIG Summary: Fortinet FortiGate Firewall NDM Security Technical Implementation Guide Version: 1 Release: 5 Benchmark Date: 05 Jan 2026:

The FortiGate device must prohibit installation of software without explicit privileged status.

DISA Rule

SV-234188r984110_rule

Vulnerability Number

V-234188

Group Title

SRG-APP-000378-NDM-000302

Rule Version

FGFW-ND-000145

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

To limit the System access to existing low-privileged administrators, log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Administrators.
3. Identify the admin role that has unauthorized access to System settings.
4. Select the admin role and hover over the profile assigned to the role.
5. Click Edit.
6. On System access permission, click None or Read only.
7. Click OK to save.

Repeat this process to define all the Administrators needed to meet privilege separation requirements for the organization.

Check Contents

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Administrators.
3. Identify the administrator that is not authorized to access System Settings and hover over the profile assigned to the role.
4. Click Edit.
5. Verify that the permission to System is set to Read or None.

If any unauthorized administrator has Read/Write access to System, this is a finding.

Vulnerability Number

V-234188

Documentable

False

Rule Version

FGFW-ND-000145

Severity Override Guidance

Log in to the FortiGate GUI with Super-Admin privilege.

1. Click System.
2. Click Administrators.
3. Identify the administrator that is not authorized to access System Settings and hover over the profile assigned to the role.
4. Click Edit.
5. Verify that the permission to System is set to Read or None.

If any unauthorized administrator has Read/Write access to System, this is a finding.

Check Content Reference

M

Target Key

5260