STIGQter STIGQter: STIG Summary: Riverbed NetProfiler Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Riverbed NetProfiler must enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 30 minutes, at a minimum.

DISA Rule

SV-256073r960840_rule

Vulnerability Number

V-256073

Group Title

SRG-APP-000065-NDM-000214

Rule Version

RINP-DM-000008

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Go to Administration >> Account Management >> User Accounts.

Click "Settings".

Under "Log-in Settings", change the "Number of log-in attempts before account is locked" to "3", and change the "Number of minutes to keep account locked" to "30".

Click "OK" to save the settings.

Note that the DOD minimum setting is 15; however, the product minimum is 30.

Check Contents

Go to Administration >> Account Management >> User Accounts.

Click "Settings".

Check under "Log-in Settings".

If the "Number of log-in attempts before an account is locked" is not set to "3", and the "Number of minutes to keep account locked" is not set to "30", this is a finding.

Vulnerability Number

V-256073

Documentable

False

Rule Version

RINP-DM-000008

Severity Override Guidance

Go to Administration >> Account Management >> User Accounts.

Click "Settings".

Check under "Log-in Settings".

If the "Number of log-in attempts before an account is locked" is not set to "3", and the "Number of minutes to keep account locked" is not set to "30", this is a finding.

Check Content Reference

M

Target Key

5514