STIGQter STIGQter: STIG Summary: Dragos Platform 2.x Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Apr 2026:

Dragos must allow only the individuals appointed by the information system security manager (ISSM) to have full admin rights to the system.

DISA Rule

SV-270952r1057499_rule

Vulnerability Number

V-270952

Group Title

SRG-APP-000156

Rule Version

DRAG-OT-000610

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Provide the list of individuals assigned by the ISSM to be members of the admin role to the Dragos administrator.

Provide the list of individuals assigned by the ISSM to be members of the admin role to the LDAP administrator to add to the LDAP group mapped to the admin role.

Create user accounts and assign the admin role for users provided in the lists.

Check Contents

Obtain the LDAP group name mapped to the admin role.

Request from the LDAP administrator the group membership of this LDAP group, and compare to the list of individuals appointed by the ISSM.

If users that are not defined by the ISSM as requiring admin rights are present in the admin role membership, this is a finding.

Vulnerability Number

V-270952

Documentable

False

Rule Version

DRAG-OT-000610

Severity Override Guidance

Obtain the LDAP group name mapped to the admin role.

Request from the LDAP administrator the group membership of this LDAP group, and compare to the list of individuals appointed by the ISSM.

If users that are not defined by the ISSM as requiring admin rights are present in the admin role membership, this is a finding.

Check Content Reference

M

Target Key

5675