STIGQter STIGQter: STIG Summary: SPEC Innovations Innoslate 4.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 08 Sep 2022:

Innoslate must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

DISA Rule

SV-254089r845243_rule

Vulnerability Number

V-254089

Group Title

SRG-APP-000033

Rule Version

SPEC-IN-000080

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Sign in With Admin Account.
2. Enter Admin Dashboard.
3. Click on the "Organization" tab.
4. Find the "Roles" section.
5. Select the role to verify.
6. Verify via checkboxes that the role has the correct permissions applied.
7. Click "Edit" if changes are needed.
8. Select the appropriate role permissions to separate Administrative Users from End Users.
9. Click "Update".
10. Verify changes were made.

Check Contents

1. Sign in With Admin Account.
2. Enter Admin Dashboard.
3. Click on the "Organization" tab.
4. Find the "Roles" section.
5. Select the role to verify.
6. Ensure Administrative roles are separated from End User roles. Otherwise, this is a finding.

Vulnerability Number

V-254089

Documentable

False

Rule Version

SPEC-IN-000080

Severity Override Guidance

1. Sign in With Admin Account.
2. Enter Admin Dashboard.
3. Click on the "Organization" tab.
4. Find the "Roles" section.
5. Select the role to verify.
6. Ensure Administrative roles are separated from End User roles. Otherwise, this is a finding.

Check Content Reference

M

Target Key

5481