STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x NDM Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

Sentry must enforce access restrictions associated with changes to the system components.

DISA Rule

SV-251003r1028241_rule

Vulnerability Number

V-251003

Group Title

SRG-APP-000516-NDM-000335

Rule Version

MOIS-ND-000930

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure that only authorized administrators have permissions for changes, deletions, and updates on the Sentry.

1. Log in to System Manager.
2. Go to Security >> identity Source >> Local Users.
3. Click "Add" to add authorized users.
4. If unauthorized users are listed, click the check box next to the unauthorized user and click "Delete".

Check Contents

Verify that only authorized administrators have permissions for changes, deletions, and updates on the Sentry.

1. Log in to System Manager.
2. Go to Security >> Local Users.
3. Verify no unauthorized users are listed.

If unauthorized users are listed, this is a finding.

Vulnerability Number

V-251003

Documentable

False

Rule Version

MOIS-ND-000930

Severity Override Guidance

Verify that only authorized administrators have permissions for changes, deletions, and updates on the Sentry.

1. Log in to System Manager.
2. Go to Security >> Local Users.
3. Verify no unauthorized users are listed.

If unauthorized users are listed, this is a finding.

Check Content Reference

M

Target Key

5438