STIGQter STIGQter: STIG Summary: Arctic Wolf CylanceON-PREM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 27 May 2025:

CylanceON-PREM must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.

DISA Rule

SV-272636r1113520_rule

Vulnerability Number

V-272636

Group Title

SRG-APP-000340

Rule Version

CYLN-OP-000685

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Remove any local users except for the break-glass/Admin user. Administrator privileges are required.

1. Log in to the admin console.
2. Navigate to ACCESS MANAGEMENT >> User Management.
3. Under "Action", click the kebab icon.
4. Select "Delete".
5. Click "Remove User".

Edit the break-glass/Admin user to not use a default name or password. Protect these credentials in accordance with internal policies.

Check Contents

Verify that only admin break-glass user is local.

1. Log in to the admin console.
2. Navigate to ACCESS MANAGEMENT >> User Management.
3. Observe the list of users.

If any users other than break-glass/Admin user exist, this is a finding.

If the break-glass/Admin user is using the default name or password, this is a finding.

Vulnerability Number

V-272636

Documentable

False

Rule Version

CYLN-OP-000685

Severity Override Guidance

Verify that only admin break-glass user is local.

1. Log in to the admin console.
2. Navigate to ACCESS MANAGEMENT >> User Management.
3. Observe the list of users.

If any users other than break-glass/Admin user exist, this is a finding.

If the break-glass/Admin user is using the default name or password, this is a finding.

Check Content Reference

M

Target Key

5692