STIGQter STIGQter: STIG Summary: Soaring Software Solutions TCMax 9.x Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 26 Feb 2026:

For password-based authentication, TCMax must require immediate selection of a new password upon account recovery.

DISA Rule

SV-281379r1186169_rule

Vulnerability Number

V-281379

Group Title

SRG-APP-000855

Rule Version

TCMA-09-000301

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using an account of appropriate privileges to access TCMax, go to Settings >> User Options.

2. Click the "Configure" menu option at the top of the window, then click "Account Security Policy".

3. Click the "Account Lockout" tab.

4. Check the "Enable Account Lockout Policy" box.

5. Check the "Force Reset after User Reactivation" box.

6. Click "Save".

Check Contents

1. Using an account of appropriate privileges to access TCMax, go to Settings >> User Options.

2. Click the "Configure" menu option at the top of the window, then click "Account Security Policy".

3. Click the "Account Lockout" tab.

If the "Enable Account Lockout Policy" box is unchecked, or the "Force Reset after User Reactivation" box is unchecked, this is a finding.

Vulnerability Number

V-281379

Documentable

False

Rule Version

TCMA-09-000301

Severity Override Guidance

1. Using an account of appropriate privileges to access TCMax, go to Settings >> User Options.

2. Click the "Configure" menu option at the top of the window, then click "Account Security Policy".

3. Click the "Account Lockout" tab.

If the "Enable Account Lockout Policy" box is unchecked, or the "Force Reset after User Reactivation" box is unchecked, this is a finding.

Check Content Reference

M

Target Key

5734