STIGQter STIGQter: STIG Summary: Arctic Wolf CylanceON-PREM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

CylanceON-PREM must be configured with only one local Role to be used by the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-272633r1113481_rule

Vulnerability Number

V-272633

Group Title

SRG-APP-000233

Rule Version

CYLN-OP-000510

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove any local Roles except for Administrator (break-glass user role). Administrator privileges are required.

1. Log in to the admin console.
2. Navigate to ACCESS MANAGEMENT >> Role Management.
3. Under "Action", click the trashcan icon.
(Note: If users are associated with the Role, the trash can icon will not exist. The user will need to be deleted first. CYLN-OP-000685)
4. Click "Remove Role".

Check Contents

Verify only Administrator (break-glass user) role is local.

1. Log in to the admin console.
2. Navigate to ACCESS MANAGEMENT >> Role Management.
3. Observe the list of Roles.

If any Roles other than break-glass/Admin Role exist, this is a finding.

Vulnerability Number

V-272633

Documentable

False

Rule Version

CYLN-OP-000510

Severity Override Guidance

Verify only Administrator (break-glass user) role is local.

1. Log in to the admin console.
2. Navigate to ACCESS MANAGEMENT >> Role Management.
3. Observe the list of Roles.

If any Roles other than break-glass/Admin Role exist, this is a finding.

Check Content Reference

M

Target Key

5692