| Checked | Name | Title |
|---|
| ☐ | SV-272627r1113422_rule | CylanceON-PREM must be configured to use a third-party identity provider. |
| ☐ | SV-272628r1113425_rule | CylanceON-PREM must be configured to initiate a session timeout after 10 minutes of inactivity. |
| ☐ | SV-272629r1113430_rule | CylanceON-PREM must be configured to use TLS 1.2 or higher. |
| ☐ | SV-272630r1113685_rule | CylanceON-PREM must be configured to show the standard mandatory DOD Notice and Consent Banner before granting access to CylanceON-PREM. |
| ☐ | SV-272631r1112743_rule | Session-only-based cookies must be enabled. |
| ☐ | SV-272632r1113445_rule | CylanceON-PREM must be configured to support integration with a third-party Security Information and Event Management (SIEM) to support notifications. |
| ☐ | SV-272633r1113481_rule | CylanceON-PREM must be configured with only one local Role to be used by the account of last resort in the event the authentication server is unavailable. |
| ☐ | SV-272634r1113494_rule | CylanceON-PREM must be configured to send alerts via Simple Mail Transfer Protocol (SMTP). |
| ☐ | SV-272635r1112755_rule | CylanceON-PREM must enforce that all files accessed are evaluated against the AI model for potential threats. |
| ☐ | SV-272636r1113520_rule | CylanceON-PREM must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable. |
| ☐ | SV-272637r1113525_rule | CylanceON-PREM must be configured to use an external database if users exceed 30,000. |
| ☐ | SV-272638r1113550_rule | CylanceON-PREM must disable all functions, ports, protocols and services not required. |
| ☐ | SV-272639r1113556_rule | CylanceON-PREM must be configured with a DOD issued certificate (or another authorizing official [AO]-approved certificate). |
| ☐ | SV-272640r1113602_rule | CylanceON-PREM must be running the latest release. |
| ☐ | SV-272641r1112773_rule | CylanceON-PREM must be restarted every 30 days to invoke health checks. |
| ☐ | SV-272642r1113686_rule | All associated custom applications, including API endpoints, must be inventoried and managed. |