CylanceON-PREM must be configured to use a third-party identity provider.
DISA Rule
SV-272627r1113422_rule
Vulnerability Number
V-272627
Group Title
SRG-APP-000001
Rule Version
CYLN-OP-000010
Severity
CAT III
CCI(s)
- CCI-000054 - Limit the number of concurrent sessions for each organization-defined account and/or account type to an organization-defined number.
- CCI-000015 - Support the management of system accounts using (organization-defined automated mechanisms).
- CCI-000017 - Disable accounts when the accounts have been inactive for the organization-defined time-period.
- CCI-000213 - Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
- CCI-000044 - Enforce the organization-defined limit of consecutive invalid logon attempts by a user during the organization-defined time period.
- CCI-000162 - Protect audit information from unauthorized access.
- CCI-001493 - Protect audit tools from unauthorized access.
- CCI-000764 - Uniquely identify and authenticate organizational users and associate that unique identification with processes acting on behalf of those users.
- CCI-000765 - Implement multifactor authentication for network access to privileged accounts.
- CCI-000766 - Implement multifactor authentication for network access to non-privileged accounts.
- CCI-004046 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
- CCI-000186 - For public key-based authentication, enforce authorized access to the corresponding private key.
- CCI-000187 - For public key-based authentication, map the authenticated identity to the account of the individual or group.
- CCI-000884 - Protect nonlocal maintenance sessions by employing organization-defined authenticators that are replay resistant.
- CCI-000877 - Employ strong authentication in the establishment of nonlocal maintenance and diagnostic sessions.
- CCI-002238 - Automatically lock the account or node for either an organization-defined time period, until the locked account or node is released by an administrator, or delays the next logon prompt according to the organization-defined delay algorithm when the maximum number of unsuccessful logon attempts is exceeded.
- CCI-002007 - Prohibit the use of cached authenticators after an organization-defined time period.
- CCI-003747 - Implement organization-defined mechanisms to authenticate organization-defined remote commands.
- CCI-003627 - Disable accounts when the accounts have expired.
- CCI-003628 - Disable accounts when the accounts are no longer associated to a user.
- CCI-003629 - Disable accounts when the accounts are in violation of organizational policy.
- CCI-003638 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can pass the information to any other subjects or objects.
- CCI-003639 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can grant its privileges to other subjects.
- CCI-003641 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can choose the security attributes to be associated with newly created or revised objects.
- CCI-003642 - Enforce organization-defined discretionary access control policies over defined subjects and objects where the policy specifies that a subject that has been granted access to information can change the rules governing access control.
- CCI-004045 - Require users to be individually authenticated before granting access to the shared accounts or resources.
- CCI-004047 - Implement multi-factor authentication for local; network; and/or remote access to privileged accounts; and/or non-privileged accounts such that the device meets organization-defined strength of mechanism requirements.
- CCI-004058 - For password-based authentication, maintain a list of commonly used, expected, or compromised passwords on an organization-defined frequency.
- CCI-004059 - For password-based authentication, update the list of passwords on an organization-defined frequency.
- CCI-004060 - For password-based authentication, update the list of passwords when organizational passwords are suspected to have been compromised directly or indirectly.
- CCI-004061 - For password-based authentication, verify when users create or update passwords, that the passwords are not found on the list of commonly-used, expected, or compromised passwords in IA-5 (1) (a).
- CCI-004062 - For password-based authentication, store passwords using an approved salted key derivation function, preferably using a keyed hash.
- CCI-004063 - For password-based authentication, require immediate selection of a new password upon account recovery.
- CCI-004064 - For password-based authentication, allow user selection of long passwords and passphrases, including spaces and all printable characters.
- CCI-004065 - For password-based authentication, employ automated tools to assist the user in selecting strong password authenticators.
- CCI-004066 - For password-based authentication, enforce organization-defined composition and complexity rules.
- CCI-004068 - For public key-based authentication, implement a local cache of revocation data to support path discovery and validation.
Weight
10
Fix Recommendation
Configure CylanceON-PREM to accept authentication from an external identity provider. Administrator privileges are required.
Using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate the LDAP section.
4. Enable Identity Provider Settings.
5. Enter the identity provider information.
6. Test the connection.
7. Click the green check.
Not using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate Identity Provider Settings.
4. Enable the Identity Provider toggle.
5. Enter the identity provider information.
- Single Sign-On: This is the single sign-on or SAML response URL that is provided by the identity provider.
- Entity ID: This is the entity ID, issuer, or application name that is provided by the identity provider.
- x.509 Certificate: This is provided by the identity provider.
6. Click the green check. CylanceON-PREM will generate a Service Provider Entity ID that the identity provider will need to complete the single sign-on configuration.
Check Contents
Verify Identity Provider (IDP) settings. Administrator privileges are required.
Using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate the LDAP section.
If LDAP (an authorized IDP) is not configured correctly or is disabled, this is not a finding.
Not using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate Identity Provider Settings.
Review documentation of allowed IDPs.
If IDP settings are not configured correctly or the IDP is disabled or not authorized, this is a finding.
Vulnerability Number
V-272627
Documentable
False
Rule Version
CYLN-OP-000010
Severity Override Guidance
Verify Identity Provider (IDP) settings. Administrator privileges are required.
Using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate the LDAP section.
If LDAP (an authorized IDP) is not configured correctly or is disabled, this is not a finding.
Not using LDAP:
1. Log in to the admin console.
2. Navigate to Configuration >> Settings.
3. Locate Identity Provider Settings.
Review documentation of allowed IDPs.
If IDP settings are not configured correctly or the IDP is disabled or not authorized, this is a finding.
Check Content Reference
M
Target Key
5692