STIGQter STIGQter: STIG Summary: AvePoint DocAve 6 Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 24 Aug 2022:

DocAve must initiate a session lock after a 15-minute period of inactivity.

DISA Rule

SV-253511r836508_rule

Vulnerability Number

V-253511

Group Title

SRG-APP-000003

Rule Version

DCAV-00-000003

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the DocAve Manager Session Timeout setting.
- Log on to DocAve with admin account.
- On the Control Panel page, in the System Options section, click "Security Settings".
- Select the "System Security Policy" tab.
- Set Logon Will Expire to "15" minutes or less.
- Save the settings.

Check Contents

Check the DocAve Manager Session Timeout setting.
- Log on to DocAve with admin account.
- On the Control Panel page, in the System Options section, click "Security Settings".
- Select the "System Security Policy" tab.
- Verify Logon Will Expire is set to "15" minutes or less.

If the Logon Will Expire is not set to "15" minutes or less, this is a finding.

Vulnerability Number

V-253511

Documentable

False

Rule Version

DCAV-00-000003

Severity Override Guidance

Check the DocAve Manager Session Timeout setting.
- Log on to DocAve with admin account.
- On the Control Panel page, in the System Options section, click "Security Settings".
- Select the "System Security Policy" tab.
- Verify Logon Will Expire is set to "15" minutes or less.

If the Logon Will Expire is not set to "15" minutes or less, this is a finding.

Check Content Reference

M

Target Key

5472