| Checked | Name | Title |
|---|
| ☐ | SV-270904r1058027_rule | Dragos must configure idle timeouts at 10 minutes. |
| ☐ | SV-270910r1057994_rule | Dragos Platform must use an Identity Provider (IDP) for authentication and authorization processes. |
| ☐ | SV-270916r1057996_rule | The Dragos Platform must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system. |
| ☐ | SV-270917r1155096_rule | The publicly accessible Dragos Platform application must display the Standard Mandatory DOD Notice and Consent Banner before granting access to Dragos Platform. |
| ☐ | SV-270919r1190805_rule | The Dragos Platform must only allow local administrative and service user accounts. |
| ☐ | SV-270932r1058029_rule | The Dragos Platform must have notification and audit services installed. |
| ☐ | SV-270944r1107127_rule | The Dragos Platform must be configured to send backup audit records. |
| ☐ | SV-270945r1107130_rule | The Dragos Platform must have disk encryption enabled on a virtual machines (VMs). |
| ☐ | SV-270947r1155102_rule | Dragos Platforms must limit privileges and not allow the ability to run shell. |
| ☐ | SV-270952r1057499_rule | Dragos must allow only the individuals appointed by the information system security manager (ISSM) to have full admin rights to the system. |
| ☐ | SV-270955r1155105_rule | The Dragos Platform must configure local password policies. |
| ☐ | SV-270978r1057577_rule | Dragos must use FIPS-validated encryption and hashing algorithms to protect the confidentiality and integrity of application configuration files and user-generated data stored or aggregated on the device. |
| ☐ | SV-270993r1058013_rule | The Dragos Platform must notify system administrators and information system security officer (ISSO) of local account activity. |
| ☐ | SV-271008r1057667_rule | Dragos Platform must allocate audit record storage retention length. |
| ☐ | SV-271027r1130600_rule | The Syslog client must use TCP connections. |
| ☐ | SV-271034r1057745_rule | Dragos Platform must accept the DOD CAC or other PKI credential for identity management and personal authentication. |
| ☐ | SV-271049r1057790_rule | The Dragos Platform must only allow the use of DOD PKI established certificate authorities for verification of the establishment of protected sessions. |
| ☐ | SV-271070r1107133_rule | The Dragos Platform must alert the information system security officer (ISSO), information system security manager (ISSM), and other individuals designated by the local organization when events are detected that indicate a compromise or potential for compromise. |
| ☐ | SV-271105r1057958_rule | Before establishing a network connection with a Network Time Protocol (NTP) server, Dragos Platform must authenticate using a bidirectional, cryptographically based authentication method that uses a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the NTP server. |