STIGQter STIGQter: STIG Summary: Arctic Wolf CylanceON-PREM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

CylanceON-PREM must be configured to use a third-party identity provider.

DISA Rule

SV-272627r1113422_rule

Vulnerability Number

V-272627

Group Title

SRG-APP-000001

Rule Version

CYLN-OP-000010

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Configure CylanceON-PREM to accept authentication from an external identity provider. Administrator privileges are required.

Using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate the LDAP section.
4. Enable Identity Provider Settings.
5. Enter the identity provider information.
6. Test the connection.
7. Click the green check.

Not using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate Identity Provider Settings.
4. Enable the Identity Provider toggle.
5. Enter the identity provider information.
- Single Sign-On: This is the single sign-on or SAML response URL that is provided by the identity provider.
- Entity ID: This is the entity ID, issuer, or application name that is provided by the identity provider.
- x.509 Certificate: This is provided by the identity provider.
6. Click the green check. CylanceON-PREM will generate a Service Provider Entity ID that the identity provider will need to complete the single sign-on configuration.

Check Contents

Verify Identity Provider (IDP) settings. Administrator privileges are required.

Using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate the LDAP section.

If LDAP (an authorized IDP) is not configured correctly or is disabled, this is not a finding.

Not using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate Identity Provider Settings.

Review documentation of allowed IDPs.

If IDP settings are not configured correctly or the IDP is disabled or not authorized, this is a finding.

Vulnerability Number

V-272627

Documentable

False

Rule Version

CYLN-OP-000010

Severity Override Guidance

Verify Identity Provider (IDP) settings. Administrator privileges are required.

Using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate the LDAP section.

If LDAP (an authorized IDP) is not configured correctly or is disabled, this is not a finding.

Not using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate Identity Provider Settings.

Review documentation of allowed IDPs.

If IDP settings are not configured correctly or the IDP is disabled or not authorized, this is a finding.

Check Content Reference

M

Target Key

5692