| Checked | Name | Title |
|---|
| ☐ | SV-266064r1024595_rule | The F5 BIG-IP appliance must be configured to limit the number of concurrent sessions to the Configuration Utility to 10 or an organization-defined number. |
| ☐ | SV-266065r1024596_rule | The F5 BIG-IP appliance must terminate shared/group account credentials when members leave the group. |
| ☐ | SV-266066r1051115_rule | The F5 BIG-IP appliance must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable. |
| ☐ | SV-266067r1024598_rule | The F5 BIG-IP appliance must be configured to assign appropriate user roles or access levels to authenticated users. |
| ☐ | SV-266068r1029557_rule | The F5 BIG-IP appliance must be configured to audit the execution of privileged functions such as accounts additions and changes. |
| ☐ | SV-266069r1024600_rule | The F5 BIG-IP appliance must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for at least 15 minutes. |
| ☐ | SV-266070r1024881_rule | The F5 BIG-IP appliance must be configured to display the Standard Mandatory DOD Notice and Consent Banner upon access to the TMOS User Interface. |
| ☐ | SV-266074r1024605_rule | The F5 BIG-IP appliance must manage local audit storage capacity in accordance with organization-defined audit record storage requirements. |
| ☐ | SV-266075r1024607_rule | The F5 BIG-IP appliance must generate audit records and send records to redundant central syslog servers that are separate from the appliance. |
| ☐ | SV-266077r1024609_rule | The F5 BIG-IP appliance must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC). |
| ☐ | SV-266078r1024610_rule | The F5 BIG-IP appliance must be configured to prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization. |
| ☐ | SV-266079r1024884_rule | The F5 BIG-IP appliance must be configured to use at least two authentication servers to authenticate administrative users. |
| ☐ | SV-266080r1024886_rule | The F5 BIG-IP appliance must be running an operating system release that is currently supported by the vendor. |
| ☐ | SV-266083r1024615_rule | The F5 BIG-IP appliance must obtain its public key certificates from an appropriate certificate policy through an approved service provider. |
| ☐ | SV-266084r1043177_rule | The F5 BIG-IP appliance must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services. |
| ☐ | SV-266085r1113746_rule | The F5 BIG-IP appliance must be configured to use multifactor authentication (MFA) for interactive logins. |
| ☐ | SV-266086r1024925_rule | The F5 BIG-IP appliance must authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based. |
| ☐ | SV-266087r1024891_rule | The F5 BIG-IP appliance must enforce a minimum 15-character password length. |
| ☐ | SV-266088r1024894_rule | The F5 BIG-IP appliance must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-266089r1024622_rule | The F5 BIG-IP appliance must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-266090r1024623_rule | The F5 BIG-IP appliance must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-266091r1024624_rule | The F5 BIG-IP appliance must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-266092r1043189_rule | The F5 BIG-IP appliance must require that when a password is changed, the characters are changed in at least eight of the positions within the password. |
| ☐ | SV-266093r1024899_rule | The F5 BIG-IP appliance must prohibit the use of cached authenticators after eight hours or less. |
| ☐ | SV-266094r1024902_rule | The F5 BIG-IP appliance must be configured to use DOD approved OCSP responders or CRLs to validate certificates used for PKI-based authentication. |
| ☐ | SV-266095r1024904_rule | The F5 BIG-IP appliance must set the idle time before automatic logout to five minutes of inactivity except to fulfill documented and validated mission requirements. |
| ☐ | SV-266096r1024630_rule | The F5 BIG-IP appliance must conduct backups of the configuration at a weekly or organization-defined frequency and store on a separate device. |
| ☐ | SV-266134r1024908_rule | The F5 BIG-IP appliance must be configured to display the Standard Mandatory DOD Notice and Consent Banner when accessing via SSH. |
| ☐ | SV-266135r1024669_rule | The F5 BIG-IP appliance must be configured to restrict a consistent inbound IP for the entire management session. |