STIGQter STIGQter: STIG Summary: Ivanti Sentry 9.x ALG Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Sentry must enforce approved authorizations for controlling the flow of information within the network based on attribute-based inspection of the source, destination, and headers, of the communications traffic.

DISA Rule

SV-251009r1028172_rule

Vulnerability Number

V-251009

Group Title

SRG-NET-000018-ALG-000017

Rule Version

MOIS-AL-000020

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Sentry to enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic via MI Core labels.

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Configurations.
3. For Active Sync email use cases with Sentry, apply the Exchange or mail app configurations using the Sentry to devices via a label.
4. For App Tunnel use cases, apply app configurations using the Sentry to device via a label.

Check Contents

Verify the Sentry and MobileIron UEM is configured to enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.

MobileIron UEM applies Configurations to devices/users based on manual or dynamic labels. Verify that Configurations that leverage Sentry such as Email, VPN, Docs@Work, or any backend service which leverage Sentry as a gateway are applied to the appropriate user groups via the configurable labels. If not, this is a finding.

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Configurations.
3. Verify the Sentry related Configurations are applied to the devices accessing systems behind the Sentry.

If Configurations are misassigned to the wrong label/user groups, this is a finding.

Vulnerability Number

V-251009

Documentable

False

Rule Version

MOIS-AL-000020

Severity Override Guidance

Verify the Sentry and MobileIron UEM is configured to enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.

MobileIron UEM applies Configurations to devices/users based on manual or dynamic labels. Verify that Configurations that leverage Sentry such as Email, VPN, Docs@Work, or any backend service which leverage Sentry as a gateway are applied to the appropriate user groups via the configurable labels. If not, this is a finding.

1. Log in to the Core Admin Portal.
2. Go to Policies and Configurations >> Configurations.
3. Verify the Sentry related Configurations are applied to the devices accessing systems behind the Sentry.

If Configurations are misassigned to the wrong label/user groups, this is a finding.

Check Content Reference

M

Target Key

5439