STIGQter STIGQter: STIG Summary: HYCU Protege Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The HYCU virtual appliance must enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level in accordance with applicable policy for the device.

DISA Rule

SV-268222r1137874_rule

Vulnerability Number

V-268222

Group Title

SRG-APP-000033-NDM-000212

Rule Version

HYCU-ND-000040

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Apply the appropriate user role to the required user from one of the predefined and nonchangeable roles: Administrator, Backup Operator, Restore Operator, Backup and Restore Operator, or Viewer.

Check Contents

Review the Self-Service menu within HYCU to view accounts and user roles (Administrator, Backup Operator, Restore Operator, Backup and Restore Operator, or Viewer).

User roles have a predefined and nonchangeable set of user privileges. To check exact set of privileges of each user, navigate to Self-Service context in the HYCU UI.

Click on the question mark in the upper-right corner, followed by "Help with This Page". Scroll down to the "User Roles" section.

If users can perform more functions than those specified for their role, this is a finding.

Vulnerability Number

V-268222

Documentable

False

Rule Version

HYCU-ND-000040

Severity Override Guidance

Review the Self-Service menu within HYCU to view accounts and user roles (Administrator, Backup Operator, Restore Operator, Backup and Restore Operator, or Viewer).

User roles have a predefined and nonchangeable set of user privileges. To check exact set of privileges of each user, navigate to Self-Service context in the HYCU UI.

Click on the question mark in the upper-right corner, followed by "Help with This Page". Scroll down to the "User Roles" section.

If users can perform more functions than those specified for their role, this is a finding.

Check Content Reference

M

Target Key

5660