STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

The ICS must be configured to enforce password complexity by requiring that at least one numeric character be used.

DISA Rule

SV-258617r997512_rule

Vulnerability Number

V-258617

Group Title

SRG-APP-000168-NDM-000256

Rule Version

IVCS-NM-000470

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.
1. Check the box for "Password must have at least __ digits".
2. In the box, enter "1".
3. Click "Save Changes".

Check Contents

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.
1. Verify the setting for "Password must have at least __ digits" is checked.
2. Verify the value for the setting for "Password must have at least __ digits" is not set to "1".

If the ICS is not configured to enforce password complexity by requiring that at least one numeric character be used, this is a finding.

Vulnerability Number

V-258617

Documentable

False

Rule Version

IVCS-NM-000470

Severity Override Guidance

In the ICS Web UI, navigate to Authentication >> Auth Servers >> Administrators.
1. Verify the setting for "Password must have at least __ digits" is checked.
2. Verify the value for the setting for "Password must have at least __ digits" is not set to "1".

If the ICS is not configured to enforce password complexity by requiring that at least one numeric character be used, this is a finding.

Check Content Reference

M

Target Key

5558