STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

If SNMP is used, the ICS must be configured to use SNMPv3 with FIPS-140-2/3 validated Keyed-Hash Message Authentication Code (HMAC).

DISA Rule

SV-258602r961506_rule

Vulnerability Number

V-258602

Group Title

SRG-APP-000395-NDM-000310

Rule Version

IVCS-NM-000090

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This is applicable if SNMP is enabled. Though the entire SNMP configuration is given to prevent misconfiguration, note that this requirement is focused on the use of v3.

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.
1. Under "SNMP version data", select v3.
2. Under "Agent Properties", select SNMP Queries.
3. Define the System Name.
4. Define the System Location.
5. Define the System Contact.
6. Under "SNMPv3 Configuration" and "User 1" type the username.
7. Select the "Security Level" of Auth, Priv.
8. Select SHA as the Auth Protocol.
9. Type the Auth password.
10. Select "CFB-AES-128" as the Priv Protocol.
11. Type the Priv password.
12. Under Optional Traps, select "Critical and Major log events".
13. Click "Save Changes".

Check Contents

If SNMP is not used, this is not applicable.

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.

Under "SNMP version data", verify v2c is not selected.

If the ICS does not use properly configured SNMPv3, this is a finding.

Vulnerability Number

V-258602

Documentable

False

Rule Version

IVCS-NM-000090

Severity Override Guidance

If SNMP is not used, this is not applicable.

In the ICS Web UI, navigate to System >> Log/Monitoring >> SNMP.

Under "SNMP version data", verify v2c is not selected.

If the ICS does not use properly configured SNMPv3, this is a finding.

Check Content Reference

M

Target Key

5558