STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

The ICS must be configured to send admin log data to a redundant central log server.

DISA Rule

SV-258599r961863_rule

Vulnerability Number

V-258599

Group Title

SRG-APP-000516-NDM-000350

Rule Version

IVCS-NM-000030

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the ICS with the address information for the redundant central log servers.

In the ICS Web UI:
1. Navigate to System >> Log/Monitoring >> Events >> Settings.
2. Under "Syslog Servers" add an IP address/server name/IP.
3. Set the facility to LOCAL0.
4. Set type to TLS.
5. If a client cert is required for the syslog server, select the client certificate to use for the syslog traffic. If none exists, import the DOD-signed client key pair to the ICS under System >> Configuration >> Certificates >> Client Auth Certificates.
6. Set the standard filer.
7. Set the source interface as the management interface.
8. Click "Add".
9. Click "Save Changes".
10. Repeat these steps for the admin logs under System >> Log/Monitoring >> Admin Access >> Settings.
11. Repeat these steps to add a redundant syslog server.

Check Contents

Verify the ICS is configured with address information so it sends admin log event records to a central log server.

In the ICS Web UI, navigate to System >> Log/Monitoring >> Events >> Settings.

Under "Syslog Servers", verify a server name/IP address, facility of LOCAL0, type TLS, and the management source interface are defined.

In the ICS Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings.

Under "Syslog Servers", verify server names/IP addresses are added. Also ensure facility of LOCAL0, type TLS, and them management source interface are not defined.

If the ICS is not configured to send log admin log events data to redundant central log servers, this is a finding.

Vulnerability Number

V-258599

Documentable

False

Rule Version

IVCS-NM-000030

Severity Override Guidance

Verify the ICS is configured with address information so it sends admin log event records to a central log server.

In the ICS Web UI, navigate to System >> Log/Monitoring >> Events >> Settings.

Under "Syslog Servers", verify a server name/IP address, facility of LOCAL0, type TLS, and the management source interface are defined.

In the ICS Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings.

Under "Syslog Servers", verify server names/IP addresses are added. Also ensure facility of LOCAL0, type TLS, and them management source interface are not defined.

If the ICS is not configured to send log admin log events data to redundant central log servers, this is a finding.

Check Content Reference

M

Target Key

5558