| Checked | Name | Title |
|---|
| ☐ | SV-253510r836505_rule | DocAve must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types. |
| ☐ | SV-253511r836508_rule | DocAve must initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-253512r836511_rule | DocAve must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access. |
| ☐ | SV-253513r836514_rule | DocAve must provide automated mechanisms for supporting account management functions. |
| ☐ | SV-253514r841862_rule | DocAve must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments. |
| ☐ | SV-253515r836520_rule | DocAve must use multifactor authentication for network access to privileged accounts. |
| ☐ | SV-253516r836523_rule | The underlying IIS platform must be configured for Smart Card (CAC) Authorization. |
| ☐ | SV-253517r836526_rule | DocAve must control remote access methods. |
| ☐ | SV-253518r836529_rule | DocAve must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions. |