STIGQter STIGQter: STIG Summary:

AvePoint DocAve 6 Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 24 Aug 2022

CheckedNameTitle
SV-253510r836505_ruleDocAve must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
SV-253511r836508_ruleDocAve must initiate a session lock after a 15-minute period of inactivity.
SV-253512r836511_ruleDocAve must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access.
SV-253513r836514_ruleDocAve must provide automated mechanisms for supporting account management functions.
SV-253514r841862_ruleDocAve must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
SV-253515r836520_ruleDocAve must use multifactor authentication for network access to privileged accounts.
SV-253516r836523_ruleThe underlying IIS platform must be configured for Smart Card (CAC) Authorization.
SV-253517r836526_ruleDocAve must control remote access methods.
SV-253518r836529_ruleDocAve must only allow the use of DoD PKI-established certificate authorities for verification of the establishment of protected sessions.