STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirement.

DISA Rule

SV-250996r1028233_rule

Vulnerability Number

V-250996

Group Title

SRG-APP-000190-NDM-000267

Rule Version

MOIS-ND-000550

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the Sentry to terminate the connection associated with a device management session at the end of the session or after 10 minutes of inactivity.

1. Log in to Sentry.
2. Go to Settings >> CLI.
3. Within CLI Configuration, input "10" for CLI Session Timeout(minutes).
4. Click "Apply".

Check Contents

The Sentry System Manager has two interfaces, a CLI restricted shell and web-based GUI. In the Sentry MICS portal, verify that the Sentry CLI timeout is set to 10 minutes.

1. Log in to Sentry.
2. Go to Settings >> CLI.
3. Within CLI Configuration, verify the CLI Session Timeout(minutes) is set to greater than 10 minutes.

If the CLI Session Timeout(minutes) is not set to greater than 10 minutes, this is a finding.

Vulnerability Number

V-250996

Documentable

False

Rule Version

MOIS-ND-000550

Severity Override Guidance

The Sentry System Manager has two interfaces, a CLI restricted shell and web-based GUI. In the Sentry MICS portal, verify that the Sentry CLI timeout is set to 10 minutes.

1. Log in to Sentry.
2. Go to Settings >> CLI.
3. Within CLI Configuration, verify the CLI Session Timeout(minutes) is set to greater than 10 minutes.

If the CLI Session Timeout(minutes) is not set to greater than 10 minutes, this is a finding.

Check Content Reference

M

Target Key

5438