STIGQter STIGQter: STIG Summary: Soaring Software Solutions TCMax 9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Feb 2026:

TCMax must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).

DISA Rule

SV-281370r1186141_rule

Vulnerability Number

V-281370

Group Title

SRG-APP-000148

Rule Version

TCMA-09-000052

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using an account of appropriate privileges to access TCMax, go to Settings >> Options >> General tab.

2. Under "Login and User Options", enable the following:
- "Require someone to be logged in before you can perform an issue or turn-in".
- "Do not allow access to log search screen without logging in".
- "Restrict reports to those with permission only".
- "Hide user id field on all screens".

3. Click "Save".

Check Contents

1. Using an account of appropriate privileges to access TCMax, go to Settings >> Options >> General tab.

2. Under "Login and User Options", verify the following are enabled:
- "Require someone to be logged in before you can perform an issue or turn-in".
- "Do not allow access to log search screen without logging in".
- "Restrict reports to those with permission only".
- "Hide user id field on all screens".

If any of these options are disabled, this is a finding.

Vulnerability Number

V-281370

Documentable

False

Rule Version

TCMA-09-000052

Severity Override Guidance

1. Using an account of appropriate privileges to access TCMax, go to Settings >> Options >> General tab.

2. Under "Login and User Options", verify the following are enabled:
- "Require someone to be logged in before you can perform an issue or turn-in".
- "Do not allow access to log search screen without logging in".
- "Restrict reports to those with permission only".
- "Hide user id field on all screens".

If any of these options are disabled, this is a finding.

Check Content Reference

M

Target Key

5734