STIGQter STIGQter: STIG Summary: Symantec Edge SWG ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Nov 2025:

The Edge SWG providing user authentication intermediary services must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.

DISA Rule

SV-279216r1170672_rule

Vulnerability Number

V-279216

Group Title

SRG-NET-000337-ALG-000096

Rule Version

SYME-00-009200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Go to "Authentication Reams and Domains".
3. Select the "CAC/Certificate" realm.
4. Under "Advanced Setting", click "Show".
5. Check the setting "Use the same refresh time for all".
6. Under "Surrogate refresh time" set it to at least "600 seconds", but the site policies may require less.
7. Click "Apply and Save".

Check Contents

1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Go to "Authentication Reams and Domains".
3. Select the "CAC/Certificate" realm.
4. Under "Advanced Setting", click "Show".

If the setting "Use the same refresh time for all" is not checked, this is a finding.

If it is checked, and the "Surrogate refresh time" is not set to at least "600 seconds", this is a finding.

Vulnerability Number

V-279216

Documentable

False

Rule Version

SYME-00-009200

Severity Override Guidance

1. In the Edge SWG Web UI, navigate to the Configuration tab.
2. Go to "Authentication Reams and Domains".
3. Select the "CAC/Certificate" realm.
4. Under "Advanced Setting", click "Show".

If the setting "Use the same refresh time for all" is not checked, this is a finding.

If it is checked, and the "Surrogate refresh time" is not set to at least "600 seconds", this is a finding.

Check Content Reference

M

Target Key

5725