STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must enforce a minimum 15-character password length.

DISA Rule

SV-251407r1004728_rule

Vulnerability Number

V-251407

Group Title

SRG-APP-000164-UEM-000094

Rule Version

IMIC-11-004800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure a 15-character length for local user accounts:

1. Log in to the Core console.
2. Security >> Password Policy.
3. Set Min Password Length to 15.

Check Contents

Verify a 15-character length for local user accounts has been configured:

1. Log in to the Core console.
2. Security >> Password Policy.
3. Verify the Min Password Length is set to 15.

If the Min Password Length is not set to 15, this is a finding.

Vulnerability Number

V-251407

Documentable

False

Rule Version

IMIC-11-004800

Severity Override Guidance

Verify a 15-character length for local user accounts has been configured:

1. Log in to the Core console.
2. Security >> Password Policy.
3. Verify the Min Password Length is set to 15.

If the Min Password Length is not set to 15, this is a finding.

Check Content Reference

M

Target Key

5445