STIGQter STIGQter: STIG Summary: AvePoint DocAve 6 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Aug 2022:

DocAve must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.

DISA Rule

SV-253510r836505_rule

Vulnerability Number

V-253510

Group Title

SRG-APP-000001

Rule Version

DCAV-00-000001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DocAve Manager Maximum User Session setting.
- Log on to DocAve with admin account.
- On the Control Panel page, in the System Options section, click "Security Settings".
- Select the "System Security Policy" tab.
- Set Maximum number of user sessions to "3" or less.
- Save the settings.

Check Contents

Check the DocAve Manager Maximum User Session setting.
- Log on to DocAve with admin account.
- On the Control Panel page, in the System Options section, click "Security Settings".
- Select the "System Security Policy" tab.
- Verify that Specify a maximum number of user sessions is set to "3" or less.

If Maximum number of user sessions is not set to "3" or less, this is a finding.

Vulnerability Number

V-253510

Documentable

False

Rule Version

DCAV-00-000001

Severity Override Guidance

Check the DocAve Manager Maximum User Session setting.
- Log on to DocAve with admin account.
- On the Control Panel page, in the System Options section, click "Security Settings".
- Select the "System Security Policy" tab.
- Verify that Specify a maximum number of user sessions is set to "3" or less.

If Maximum number of user sessions is not set to "3" or less, this is a finding.

Check Content Reference

M

Target Key

5472