STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance must be configured to enable the secure cookie flag.

DISA Rule

SV-266163r1024393_rule

Vulnerability Number

V-266163

Group Title

SRG-NET-000233-ALG-000115

Rule Version

F5BI-AP-300152

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure each Access Profile to enable the Secure Cookies flag.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains tab.
6. Under Cookie Options, check "Secure".
7. Click "Update".
8. Click "Apply Access Policy".

Check Contents

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains tab.
6. Under Cookie Options, verify "Secure" is enabled.

If the F5 BIG-IP appliance APM Policy does not enable the Secure cookies flag, this is a finding.

Vulnerability Number

V-266163

Documentable

False

Rule Version

F5BI-AP-300152

Severity Override Guidance

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click the access profile name.
5. SSO/Auth Domains tab.
6. Under Cookie Options, verify "Secure" is enabled.

If the F5 BIG-IP appliance APM Policy does not enable the Secure cookies flag, this is a finding.

Check Content Reference

M

Target Key

5640