STIGQter STIGQter: STIG Summary: IBM MQ Appliance v9.0 NDM Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 05 Jun 2017: The MQ Appliance network device must prohibit the use of cached authenticators after an organization-defined time period.

DISA Rule

SV-89679r1_rule

Vulnerability Number

V-75005

Group Title

SRG-APP-000400-NDM-000313

Rule Version

MQMH-ND-001240

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Log on to the MQ Appliance WebGUI as a privileged user. Go to Administration (gear icon) >> Access >> RBM Settings.

Set Authentication Method to LDAP. Limit cache settings to an organization-defined time period.

Configure other LDAP connection settings as required.

Check Contents

Log on to the MQ Appliance WebGUI as a privileged user. Go to Administration (gear icon) >> Access >> RBM Settings.

Verify the Authentication Method is set to LDAP and the cache setting is defined and specifies the organization-defined time period.

If the Authentication Method is not set to LDAP and the cache setting does not specify the organization-defined time period, this is a finding.

Vulnerability Number

V-75005

Documentable

False

Rule Version

MQMH-ND-001240

Severity Override Guidance

Log on to the MQ Appliance WebGUI as a privileged user. Go to Administration (gear icon) >> Access >> RBM Settings.

Verify the Authentication Method is set to LDAP and the cache setting is defined and specifies the organization-defined time period.

If the Authentication Method is not set to LDAP and the cache setting does not specify the organization-defined time period, this is a finding.

Check Content Reference

M

Target Key

3243

Comments