STIGQter STIGQter: STIG Summary:

AvePoint Compliance Guardian Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 15 Mar 2023

CheckedNameTitle
SV-256839r890127_ruleCompliance Guardian must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
SV-256840r890130_ruleCompliance Guardian must initiate a session timeout after a 15-minute period of inactivity.
SV-256841r890133_ruleCompliance Guardian must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access.
SV-256842r890136_ruleCompliance Guardian must provide automated mechanisms for supporting account management functions.
SV-256843r890139_ruleCompliance Guardian must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
SV-256844r890142_ruleCompliance Guardian must use multifactor authentication for network access to privileged accounts.
SV-256845r890145_ruleCompliance Guardian must control remote access methods.
SV-256846r890148_ruleCompliance Guardian must accept FICAM-approved third-party credentials.
SV-256847r890151_ruleCompliance Guardian must conform to FICAM-issued profiles.
SV-256848r890154_ruleCompliance Guardian must only allow the use of DOD PKI established certificate authorities for verification of the establishment of protected sessions.