STIGQter STIGQter: STIG Summary: Soaring Software Solutions TCMax 9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Feb 2026:

TCMax must enforce password complexity by requiring that at least one uppercase letter, one lowercase letter, and number, and one special character be used.

DISA Rule

SV-281372r1186146_rule

Vulnerability Number

V-281372

Group Title

SRG-APP-000166

Rule Version

TCMA-09-000063

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using an account of appropriate privileges to access TCMax, go to Settings >> User Options.

2. Click the "Configure" menu option at the top of the window, then click "Account Security Policy".

3. Check the "Enable Password Enforcement Policy" box and check the "Complex Password" box.

4. Click "Save".

Check Contents

1. Using an account of appropriate privileges to access TCMax, go to Settings >> User Options.

2. Click the "Configure" menu option at the top of the window, then click "Account Security Policy".

On the Password Enforcement tab, if the "Enable Password Enforcement Policy" box or the "Complex Password" is unchecked, this is a finding.

Vulnerability Number

V-281372

Documentable

False

Rule Version

TCMA-09-000063

Severity Override Guidance

1. Using an account of appropriate privileges to access TCMax, go to Settings >> User Options.

2. Click the "Configure" menu option at the top of the window, then click "Account Security Policy".

On the Password Enforcement tab, if the "Enable Password Enforcement Policy" box or the "Complex Password" is unchecked, this is a finding.

Check Content Reference

M

Target Key

5734