STIGQter STIGQter: STIG Summary: AvePoint Compliance Guardian Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 15 Mar 2023:

Compliance Guardian must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.

DISA Rule

SV-256839r890127_rule

Vulnerability Number

V-256839

Group Title

SRG-APP-000001

Rule Version

APCG-00-000001

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Compliance Guardian Manager Maximum User Session setting.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the System Configuration section, click "General Settings".
- Select "Security - System Security Policy".
- Set the maximum simultaneous logons for the same user option to "5".
- Save the settings.

Check Contents

Check the Compliance Guardian Manager Maximum User Session setting.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the System Configuration section, click "General Settings".
- Select "Security - System Security Policy".
- Verify that the "Specify a maximum simultaneous logons for the same user" is set to "5".

If the maximum number of user sessions is higher than 5, this is a finding.

Vulnerability Number

V-256839

Documentable

False

Rule Version

APCG-00-000001

Severity Override Guidance

Check the Compliance Guardian Manager Maximum User Session setting.
- Log on to Compliance Guardian with admin account.
- On the Control Panel page in the System Configuration section, click "General Settings".
- Select "Security - System Security Policy".
- Verify that the "Specify a maximum simultaneous logons for the same user" is set to "5".

If the maximum number of user sessions is higher than 5, this is a finding.

Check Content Reference

M

Target Key

5531