STIGQter STIGQter: STIG Summary:

Dragos Platform 2.x Security Technical Implementation Guide

Version: 1

Release: 6 Benchmark Date: 01 Apr 2026

CheckedNameTitle
SV-270904r1058027_ruleDragos must configure idle timeouts at 10 minutes.
SV-270910r1057994_ruleDragos Platform must use an Identity Provider (IDP) for authentication and authorization processes.
SV-270916r1057996_ruleThe Dragos Platform must display the Standard Mandatory DOD Notice and Consent Banner before granting local or remote access to the system.
SV-270917r1155096_ruleThe publicly accessible Dragos Platform application must display the Standard Mandatory DOD Notice and Consent Banner before granting access to Dragos Platform.
SV-270919r1190805_ruleThe Dragos Platform must only allow local administrative and service user accounts.
SV-270932r1058029_ruleThe Dragos Platform must have notification and audit services installed.
SV-270944r1107127_ruleThe Dragos Platform must be configured to send backup audit records.
SV-270945r1107130_ruleThe Dragos Platform must have disk encryption enabled on a virtual machines (VMs).
SV-270947r1155102_ruleDragos Platforms must limit privileges and not allow the ability to run shell.
SV-270952r1057499_ruleDragos must allow only the individuals appointed by the information system security manager (ISSM) to have full admin rights to the system.
SV-270955r1155105_ruleThe Dragos Platform must configure local password policies.
SV-270978r1057577_ruleDragos must use FIPS-validated encryption and hashing algorithms to protect the confidentiality and integrity of application configuration files and user-generated data stored or aggregated on the device.
SV-270993r1058013_ruleThe Dragos Platform must notify system administrators and information system security officer (ISSO) of local account activity.
SV-271008r1057667_ruleDragos Platform must allocate audit record storage retention length.
SV-271027r1130600_ruleThe Syslog client must use TCP connections.
SV-271034r1057745_ruleDragos Platform must accept the DOD CAC or other PKI credential for identity management and personal authentication.
SV-271049r1057790_ruleThe Dragos Platform must only allow the use of DOD PKI established certificate authorities for verification of the establishment of protected sessions.
SV-271070r1107133_ruleThe Dragos Platform must alert the information system security officer (ISSO), information system security manager (ISSM), and other individuals designated by the local organization when events are detected that indicate a compromise or potential for compromise.
SV-271105r1057958_ruleBefore establishing a network connection with a Network Time Protocol (NTP) server, Dragos Platform must authenticate using a bidirectional, cryptographically based authentication method that uses a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the NTP server.