STIGQter STIGQter: STIG Summary:

HP FlexFabric Switch NDM Security Technical Implementation Guide

Version: 1

Release: 4 Benchmark Date: 02 Jul 2025

CheckedNameTitle
SV-217426r960735_ruleThe HP FlexFabric Switch must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
SV-217427r960777_ruleThe HP FlexFabric Switch must automatically audit account creation.
SV-217428r960780_ruleThe HP FlexFabric Switch must automatically audit account modification.
SV-217429r960783_ruleThe HP FlexFabric Switch must automatically audit account disabling actions.
SV-217430r960786_ruleThe HP FlexFabric Switch must automatically audit account removal actions.
SV-217431r960792_ruleThe HP FlexFabric Switch must enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level in accordance with applicable policy for the device.
SV-217432r960801_ruleThe HP FlexFabric Switch must enforce approved authorizations for controlling the flow of management information within the HP FlexFabric Switch based on information flow control policies.
SV-217433r960840_ruleThe HP FlexFabric Switch must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-217434r960843_ruleThe HP FlexFabric Switch must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
SV-217435r960846_ruleThe HP FlexFabric Switch must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log on for further access.
SV-217436r960864_ruleThe HP FlexFabric Switch must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.
SV-217438r960885_ruleThe HP FlexFabric Switch must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-217439r960888_ruleThe HP FlexFabric Switch must initiate session auditing upon startup.
SV-217440r960891_ruleThe HP FlexFabric Switch must produce audit log records containing sufficient information to establish what type of event occurred.
SV-217441r960894_ruleThe HP FlexFabric Switch must produce audit records containing information to establish when (date and time) the events occurred.
SV-217442r960897_ruleThe HP FlexFabric Switch must produce audit records containing information to establish where the events occurred.
SV-217443r960900_ruleThe HP FlexFabric Switch must produce audit log records containing information to establish the source of events.
SV-217444r960903_ruleThe HP FlexFabric Switch must produce audit records that contain information to establish the outcome of the event.
SV-217445r960906_ruleThe HP FlexFabric Switch must generate audit records containing information that establishes the identity of any individual or process associated with the event.
SV-217446r960909_ruleThe HP FlexFabric Switch must generate audit records containing the full-text recording of privileged commands.
SV-217447r960927_ruleThe HP FlexFabric Switch must use internal system clocks to generate time stamps for audit records.
SV-217448r960933_ruleThe HP FlexFabric Switch must protect audit information from unauthorized modification.
SV-217449r960936_ruleThe HP FlexFabric Switch must protect audit information from unauthorized deletion.
SV-217451r1043177_ruleThe HP FlexFabric Switch must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
SV-217452r1113774_ruleThe HP FlexFabric Switch must enforce a minimum 15-character password length.
SV-217453r1113778_ruleIf multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one uppercase character be used.
SV-217454r1113781_ruleIf multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one lowercase character be used.
SV-217455r1113782_ruleIf multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one numeric character be used.
SV-217456r1113783_ruleIf multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one special character be used.
SV-217457r961068_ruleThe HP FlexFabric Switch must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirements.
SV-217458r961224_ruleNetwork devices must provide a logoff capability for administrator-initiated communication sessions.
SV-217459r961290_ruleThe HP FlexFabric Switch must automatically audit account enabling actions.
SV-217460r961317_ruleIf the HP FlexFabric Switch uses discretionary access control, the HP FlexFabric Switch must enforce organization-defined discretionary access control policies over defined subjects and objects.
SV-217461r987662_ruleIf the HP FlexFabric Switch uses role-based access control, the HP FlexFabric Switch must enforce organization-defined role-based access control policies over defined subjects and objects.
SV-217463r961392_ruleThe HP FlexFabric Switch must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-217464r961401_ruleThe HP FlexFabric Switch must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
SV-217465r987682_ruleThe HP FlexFabric Switch must be configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.
SV-217466r961443_ruleThe HP FlexFabric Switch must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
SV-217467r961446_ruleThe HP FlexFabric Switch must record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.
SV-217468r961554_ruleApplications used for nonlocal maintenance sessions must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
SV-217469r961557_ruleApplications used for nonlocal maintenance sessions must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
SV-217470r961620_ruleThe HP FlexFabric Switch must protect against or limit the effects of all known types of Denial of Service (DoS) attacks on the HP FlexFabric Switch management network by employing organization-defined security safeguards.
SV-217471r987719_ruleIf the HP FlexFabric Switch uses mandatory access control, the HP FlexFabric Switch must enforce organization-defined mandatory access control policies over all subjects and objects.
SV-217472r961800_ruleThe HP FlexFabric Switch must generate audit records when successful/unsuccessful attempts to modify administrator privileges occur.
SV-217473r961812_ruleThe HP FlexFabric Switch must generate audit records when successful/unsuccessful attempts to delete administrator privileges occur.
SV-217474r961824_ruleThe HP FlexFabric Switch must generate audit records when successful/unsuccessful logon attempts occur.
SV-217475r961827_ruleThe HP FlexFabric Switch must generate audit records for privileged activities or other system-level access.
SV-217476r961830_ruleThe HP FlexFabric Switch must generate audit records showing starting and ending time for administrator access to the system.
SV-217477r961833_ruleThe HP FlexFabric Switch must generate audit records when concurrent logons from different workstations occur.
SV-217478r961860_ruleThe HP FlexFabric Switch must off-load audit records onto a different system or media than the system being audited.
SV-217479r961863_ruleThe HP FlexFabric Switch must generate audit log events for a locally developed list of auditable events.
SV-217480r961863_ruleThe HP FlexFabric Switch must enforce access restrictions associated with changes to the system components.
SV-217481r961863_ruleThe HP FlexFabric Switch must support organizational requirements to conduct backups of system level information contained in the information system when changes occur or weekly, whichever is sooner.
SV-217482r961863_ruleThe HP FlexFabric Switch must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-217483r961863_ruleThe HP FlexFabric Switch must have a local account that will only be used as an account of last resort with full access to the network device.
SV-217484r961863_ruleThe HP FlexFabric switch must be configured to utilize an authentication server for the purpose of authenticating privilege users, managing accounts, and to centrally verify authentication settings and Personal Identity Verification (PIV) credentials.
SV-217485r961863_ruleThe HP FlexFabric switch must be configured to send log data to a syslog server for the purpose of forwarding alerts to the administrators and the ISSO.
SV-217486r961863_ruleThe HP FlexFabric switch must be configured to send SNMP traps and notifications to the SNMP manager for the purpose of sending alarms and notifying appropriate personnel as required by specific events.
SV-230161r961863_ruleThe HP FlexFabric Switch must automatically disable accounts after a 35-day period of account inactivity.
SV-230162r961863_ruleUpon successful logon, the HP FlexFabric Switch must notify the administrator of the date and time of the last logon.
SV-230163r961863_ruleUpon successful logon, the HP FlexFabric Switch must notify the administrator of the number of unsuccessful logon attempts since the last successful logon.
SV-230164r961863_ruleThe HP FlexFabric Switch must provide audit record generation capability for DoD-defined auditable events within the HP FlexFabric Switch.
SV-230165r961863_ruleThe HP FlexFabric Switch must protect audit information from any type of unauthorized read access.
SV-230166r961863_ruleThe HP FlexFabric Switch must disable identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.
SV-230167r1113775_ruleThe HP FlexFabric Switch must prohibit password reuse for a minimum of five generations.
SV-230168r1113784_ruleThe HP FlexFabric Switch must enforce 24 hours/1 day as the minimum password lifetime.
SV-230169r1113785_ruleThe HP FlexFabric Switch must enforce a 60-day maximum password lifetime restriction.
SV-230170r961863_ruleThe HP FlexFabric Switch, when utilizing PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.
SV-230171r961863_ruleThe HP FlexFabric Switch must map the authenticated identity to the user account for PKI-based authentication.
SV-230172r961863_ruleThe HP FlexFabric Switch must generate an immediate alert for account enabling actions.
SV-230173r961863_ruleThe HP FlexFabric Switch must automatically lock the account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded.
SV-230174r961863_ruleThe HP FlexFabric Switch must notify the administrator, upon successful logon (access), of the location of last logon (terminal or IP address) in addition to the date and time of the last logon (access).
SV-230175r961863_ruleThe HP FlexFabric Switch must generate an immediate alert when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity.
SV-230176r961863_ruleThe HP FlexFabric Switch must compare internal information system clocks at least every 24 hours with an authoritative time server.
SV-230177r961863_ruleThe HP FlexFabric Switch must synchronize internal information system clocks to the authoritative time source when the time difference is greater than the organization-defined time period.
SV-230178r961863_ruleThe HP FlexFabric Switch must allow the use of a temporary password for system logons with an immediate change to a permanent password.
SV-230179r961863_ruleThe HP FlexFabric Switch must generate audit records for all account creations, modifications, disabling, and termination events.
SV-230180r961863_ruleThe HP FlexFabric Switch must notify the administrator of the number of successful logon attempts occurring during an organization-defined time period.
SV-230181r961863_ruleThe HP FlexFabric Switch must employ automated mechanisms to assist in the tracking of security incidents.