STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

The ICS must be configured to enforce a minimum 15-character password length.

DISA Rule

SV-258614r997510_rule

Vulnerability Number

V-258614

Group Title

SRG-APP-000164-NDM-000252

Rule Version

IVCS-NM-000440

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.
1. For minimum length, type "15".
2. Click "Save Changes".

Check Contents

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.

If the minimum length is not 15 characters, this is a finding.

Vulnerability Number

V-258614

Documentable

False

Rule Version

IVCS-NM-000440

Severity Override Guidance

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.

If the minimum length is not 15 characters, this is a finding.

Check Content Reference

M

Target Key

5558