STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

The ICS must be configured to enforce password complexity by requiring that at least one special character be used.

DISA Rule

SV-258606r997508_rule

Vulnerability Number

V-258606

Group Title

SRG-APP-000169-NDM-000257

Rule Version

IVCS-NM-000190

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.
1. Enable the setting for "Password must have at least __ special characters".
2. In the box, enter "1".
3. Click "Save Changes".

Check Contents

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.
1. Verify the setting for "Password must have at least __ letters" is checked.
2. Verify the value for the setting for "Password must have at least __ special characters" is set to "1".

If the ICS does not require that at least one special character be used for passwords, this is a finding.

Vulnerability Number

V-258606

Documentable

False

Rule Version

IVCS-NM-000190

Severity Override Guidance

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.
1. Verify the setting for "Password must have at least __ letters" is checked.
2. Verify the value for the setting for "Password must have at least __ special characters" is set to "1".

If the ICS does not require that at least one special character be used for passwords, this is a finding.

Check Content Reference

M

Target Key

5558