STIGQter STIGQter: STIG Summary: Unified Endpoint Management Server Security Requirements Guide Version: 2 Release: 5 Benchmark Date: 29 Jun 2026:

The UEM server must sign policies and policy updates using a private key associated with [selection: an X509 certificate, a public key provisioned to the agent trusted by the agent] for policy verification.

DISA Rule

SV-264368r1213324_rule

Vulnerability Number

V-264368

Group Title

SRG-APP-000427

Rule Version

SRG-APP-000427-UEM-000501

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the UEM server to sign policies and policy updates using [selection: an X509 certificate, a public key provisioned to the agent] trusted by the agent for policy verification.

Check Contents

Verify the server is configured to sign policies and policy updates using [selection: an X509 certificate, a public key provisioned to the agent] trusted by the agent for policy verification.

If the UEM server is not signing all policy updates using [selection: an X509 certificate, a public key provisioned to the agent] trusted by the agent for policy verification, this is a finding.

Vulnerability Number

V-264368

Documentable

False

Rule Version

SRG-APP-000427-UEM-000501

Severity Override Guidance

Verify the server is configured to sign policies and policy updates using [selection: an X509 certificate, a public key provisioned to the agent] trusted by the agent for policy verification.

If the UEM server is not signing all policy updates using [selection: an X509 certificate, a public key provisioned to the agent] trusted by the agent for policy verification, this is a finding.

Check Content Reference

M

Target Key

5269