STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

The ICS must be configured to audit the execution of privileged functions such as accounts additions and changes.

DISA Rule

SV-258601r997507_rule

Vulnerability Number

V-258601

Group Title

SRG-APP-000343-NDM-000289

Rule Version

IVCS-NM-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Enable logging for admin event actions.

In the ICS Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings.
1. Check the box for Administrator changes under the section "Select Events to Log".
2. Click "Save Changes".

Check Contents

In the ICS Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings, under the section "Select Events to Log".

If Administrator changes is enabled for events logging, this is a finding.

Vulnerability Number

V-258601

Documentable

False

Rule Version

IVCS-NM-000060

Severity Override Guidance

In the ICS Web UI, navigate to System >> Log/Monitoring >> Admin Access >> Settings, under the section "Select Events to Log".

If Administrator changes is enabled for events logging, this is a finding.

Check Content Reference

M

Target Key

5558