STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry device must enforce a minimum 15-character password length.

DISA Rule

SV-250989r1029559_rule

Vulnerability Number

V-250989

Group Title

SRG-APP-000164-NDM-000252

Rule Version

MOIS-ND-000420

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Sentry Local User Password Policy to enforce a minimum 15-character password.

1. Log in to Sentry System Manager portal.
2. Go to the "Security" tab.
3. Go to Password Policy.
4. Set the "Minimum Password Length" value to 15 or more.

Check Contents

Review Sentry configuration to verify that a minimum 15-character password is set.

1. Log in to Sentry System Manager portal.
2. Go to the "Security" tab.
3. Go to Identity Source >> Password Policy.
4. Verify the "Minimum Password Length" is set to 15 or more.

If the password character length is not set 15 or more, this is a finding.

Vulnerability Number

V-250989

Documentable

False

Rule Version

MOIS-ND-000420

Severity Override Guidance

Review Sentry configuration to verify that a minimum 15-character password is set.

1. Log in to Sentry System Manager portal.
2. Go to the "Security" tab.
3. Go to Identity Source >> Password Policy.
4. Verify the "Minimum Password Length" is set to 15 or more.

If the password character length is not set 15 or more, this is a finding.

Check Content Reference

M

Target Key

5438