STIGQter STIGQter: STIG Summary: Dragos Platform 2.x Security Technical Implementation Guide Version: 1 Release: 6 Benchmark Date: 01 Apr 2026:

The Dragos Platform must only allow the use of DOD PKI established certificate authorities for verification of the establishment of protected sessions.

DISA Rule

SV-271049r1057790_rule

Vulnerability Number

V-271049

Group Title

SRG-APP-000427

Rule Version

DRAG-OT-001910

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Change Certificate via GUI.

In the UI, navigate to Admin >> SiteStore Management >> Advanced Settings.

Click "Change Certificate".

Fill in the correct fields and either upload or insert the certificate.

Click "Save & Apply".

Check Contents

Open a web browser and navigate to the Dragos Platform UI.

Locate the security or certificate status indicator at the address bar.

Open the certificate information. If the certificate is signed by anyone other than DOD, PKI, or CA, this is a finding.

Vulnerability Number

V-271049

Documentable

False

Rule Version

DRAG-OT-001910

Severity Override Guidance

Open a web browser and navigate to the Dragos Platform UI.

Locate the security or certificate status indicator at the address bar.

Open the certificate information. If the certificate is signed by anyone other than DOD, PKI, or CA, this is a finding.

Check Content Reference

M

Target Key

5675