CylanceON-PREM must be configured to use TLS 1.2 or higher.
DISA Rule
SV-272629r1113430_rule
Vulnerability Number
V-272629
Group Title
SRG-APP-000014
Rule Version
CYLN-OP-000025
Severity
CAT I
CCI(s)
- CCI-000068 - Implement cryptographic mechanisms to protect the confidentiality of remote access sessions.
- CCI-001941 - Implement replay-resistant authentication mechanisms for access to privileged accounts and/or non-privileged accounts.
- CCI-000197 - For password-based authentication, transmit passwords only cryptographically-protected channels.
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-001184 - Protect the authenticity of communications sessions.
- CCI-002418 - Protect the confidentiality and/or integrity of transmitted information.
- CCI-002421 - Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission.
- CCI-002420 - Maintain the confidentiality and/or integrity of information during preparation for transmission.
- CCI-002422 - Maintain the confidentiality and/or integrity of information during reception.
- CCI-001453 - Implement cryptographic mechanisms to protect the integrity of remote access sessions.
- CCI-000185 - For public key-based authentication, validate certificates by constructing and verifying a certification path to an accepted trust anchor including checking certificate status information.
- CCI-000382 - Configure the system to prohibit or restrict the use of organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services.
Weight
10
Fix Recommendation
Configure Cipher. Administrator privileges are required.
1. Log in to the admin console.
2. Navigate to CONFIGURATION >> Settings.
3. Find CylanceON-PREM Info >> Certificate Cipher.
4. Click "Change".
5. Select "Modern Mode (TS 1.2+)".
6. Click "Update".
Check Contents
Verify Cipher configuration. Administrator privileges are required.
1. Log in to the admin console.
2. Navigate to CONFIGURATION >> Settings.
3. Find CylanceON-PREM Info >> Certificate Cipher.
If the value is not set to Modern Mode (TLS 1.2+), this is a finding.
Vulnerability Number
V-272629
Documentable
False
Rule Version
CYLN-OP-000025
Severity Override Guidance
Verify Cipher configuration. Administrator privileges are required.
1. Log in to the admin console.
2. Navigate to CONFIGURATION >> Settings.
3. Find CylanceON-PREM Info >> Certificate Cipher.
If the value is not set to Modern Mode (TLS 1.2+), this is a finding.
Check Content Reference
M
Target Key
5692