STIGQter STIGQter: STIG Summary:

Dell OS10 Switch NDM Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 10 Dec 2024

CheckedNameTitle
SV-269768r1051689_ruleThe Dell OS10 Switch must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
SV-269769r1052474_ruleThe Dell OS10 Switch must be configured to assign appropriate user roles or access levels to authenticated users.
SV-269770r1051695_ruleThe Dell OS10 Switch must enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies.
SV-269771r1051698_ruleThe Dell OS10 Switch must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
SV-269772r1051701_ruleThe Dell OS10 device must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device.
SV-269773r1051704_ruleThe Dell OS10 Switch must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by nonrepudiation.
SV-269774r1051707_ruleThe Dell OS10 Switch must initiate session auditing upon startup.
SV-269775r1051710_ruleThe Dell OS10 Switch must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
SV-269776r1051713_ruleThe Dell OS10 Switch must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.
SV-269777r1051716_ruleThe Dell OS10 Switch must be configured to disable the Bash shell.
SV-269778r1051719_ruleThe Dell OS10 Switch must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
SV-269779r1051722_ruleThe Dell OS10 Switch must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins.
SV-269780r1051725_ruleThe Dell OS10 Switch must implement replay-resistant authentication mechanisms for network access to privileged accounts.
SV-269781r1051728_ruleThe Dell OS10 Switch must enforce a minimum 15-character password length.
SV-269782r1051731_ruleThe Dell OS10 Switch must enforce password complexity by requiring that at least one uppercase character be used.
SV-269783r1051734_ruleThe Dell OS10 Switch must enforce password complexity by requiring that at least one lowercase character be used.
SV-269784r1051737_ruleThe Dell OS10 Switch must enforce password complexity by requiring that at least one numeric character be used.
SV-269785r1051740_ruleThe Dell OS10 Switch must enforce password complexity by requiring that at least one special character be used.
SV-269786r1052487_ruleThe Dell OS10 Switch must be configured to use DOD-approved OCSP responders or CRLs to validate certificates used for PKI-based authentication.
SV-269787r1052488_ruleThe Dell OS10 Switch, for PKI-based authentication, must be configured to map validated certificates to unique user accounts.
SV-269788r1051749_ruleThe Dell OS10 Switch must use FIPS 140-2 approved algorithms for authentication to a cryptographic module.
SV-269789r1051752_ruleThe Dell OS10 Switch must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.
SV-269790r1051755_ruleThe Dell OS10 Switch must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-269791r1051758_ruleThe Dell OS10 Switch must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
SV-269793r1052419_ruleThe Dell OS10 Switch must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC).
SV-269794r1051767_ruleThe Dell OS10 Switch must authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based.
SV-269795r1052420_ruleThe Dell OS10 Switch must prohibit the use of cached authenticators after an organization-defined time period.
SV-269796r1051773_ruleThe Dell OS10 Switch must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.
SV-269797r1052421_ruleThe Dell OS10 Switch must be configured to implement cryptographic mechanisms using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions.
SV-269798r1051779_ruleThe Dell OS10 Switch must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.
SV-269799r1051782_ruleThe application must install security-relevant firmware updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
SV-269800r1052422_ruleThe Dell OS10 Switch must generate log records for a locally developed list of auditable events.
SV-269801r1051788_ruleThe Dell OS10 Switch must enforce access restrictions associated with changes to the system components.
SV-269802r1052489_ruleThe Dell OS10 Switch must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-269803r1051794_ruleThe Dell OS10 Switch must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).
SV-269804r1051797_ruleThe Dell OS10 Switch must be running an operating system release that is currently supported by Dell.
SV-269805r1051800_ruleThe Dell OS10 Switch must not have any default manufacturer passwords when deployed.
SV-270643r1052343_ruleThe Dell OS10 Switch must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access.
SV-270644r1052341_ruleThe Dell OS10 Switch must be configured to synchronize internal information system clocks using redundant authoritative time sources.