| Checked | Name | Title |
|---|
| ☐ | SV-256839r890127_rule | Compliance Guardian must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types. |
| ☐ | SV-256840r890130_rule | Compliance Guardian must initiate a session timeout after a 15-minute period of inactivity. |
| ☐ | SV-256841r890133_rule | Compliance Guardian must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access. |
| ☐ | SV-256842r890136_rule | Compliance Guardian must provide automated mechanisms for supporting account management functions. |
| ☐ | SV-256843r890139_rule | Compliance Guardian must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-256844r890142_rule | Compliance Guardian must use multifactor authentication for network access to privileged accounts. |
| ☐ | SV-256845r890145_rule | Compliance Guardian must control remote access methods. |
| ☐ | SV-256846r890148_rule | Compliance Guardian must accept FICAM-approved third-party credentials. |
| ☐ | SV-256847r890151_rule | Compliance Guardian must conform to FICAM-issued profiles. |
| ☐ | SV-256848r890154_rule | Compliance Guardian must only allow the use of DOD PKI established certificate authorities for verification of the establishment of protected sessions. |