STIGQter STIGQter: STIG Summary: Ivanti Connect Secure NDM Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 01 Oct 2025:

The ICS must be configured to limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.

DISA Rule

SV-258622r960735_rule

Vulnerability Number

V-258622

Group Title

SRG-APP-000001-NDM-000200

Rule Version

IVCS-NM-000690

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

In the ICS Web UI, navigate to Administrators >> Admins Realms >> Admin Realms.
1. Click the configured admin realm being used for CAC/PKI token admin logins.
2. Click the "Authentication Policy" tab, then click "Limits".
3. In "Maximum number of sessions per user", type the number "1".
4. Click "Save Changes".

Check Contents

In the ICS Web UI, navigate to Administrators >> Admins Realms >> Admin Realms.
1. Click the configured admin realm being used for CAC/PKI token admin logins.
2. Click the "Authentication Policy" tab.
3. Click "Limits".

If there is any number other than 1 in "Maximum number of sessions per user", this is a finding.

Vulnerability Number

V-258622

Documentable

False

Rule Version

IVCS-NM-000690

Severity Override Guidance

In the ICS Web UI, navigate to Administrators >> Admins Realms >> Admin Realms.
1. Click the configured admin realm being used for CAC/PKI token admin logins.
2. Click the "Authentication Policy" tab.
3. Click "Limits".

If there is any number other than 1 in "Maximum number of sessions per user", this is a finding.

Check Content Reference

M

Target Key

5558