STIGQter STIGQter: STIG Summary:

HYCU Protege Security Technical Implementation Guide

Version: 1

Release: 3 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-268216r1038348_ruleThe HYCU virtual appliance must be configured to synchronize internal information system clocks using redundant authoritative time sources.
SV-268217r1067634_ruleThe HYCU virtual appliance must not have any default manufacturer passwords when deployed.
SV-268219r1038638_ruleThe HYCU virtual appliance must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
SV-268222r1137874_ruleThe HYCU virtual appliance must enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level in accordance with applicable policy for the device.
SV-268223r1137878_ruleIf the HYCU virtual appliance uses role-based access control, it must enforce organization-defined role-based access control policies over defined subjects and objects.
SV-268225r1137875_ruleThe HYCU virtual appliance must enforce approved authorizations for controlling the flow of management information within the appliance based on information flow control policies.
SV-268226r1038378_ruleThe HYCU virtual appliance must audit the execution of privileged functions.
SV-268227r1038750_ruleThe HYCU virtual appliance must be configured to enforce the limit of three consecutive invalid login attempts, after which time it must block any login attempt for 15 minutes.
SV-268228r1038752_ruleThe HYCU virtual appliance must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device.
SV-268229r1038748_ruleThe HYCU virtual appliance must retain the Standard Mandatory DOD Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log in for further access.
SV-268231r1038648_ruleThe HYCU virtual appliance must automatically audit account creation.
SV-268232r1038650_ruleThe HYCU virtual appliance must automatically audit account modification.
SV-268233r1038652_ruleThe HYCU virtual appliance must automatically audit account disabling actions.
SV-268234r1038654_ruleThe HYCU virtual appliance must automatically audit account removal actions.
SV-268235r1038742_ruleThe HYCU virtual appliance must be configured to use DOD-approved online certificate status protocol (OCSP) responders or certificate revocation lists (CRLs) to validate certificates used for PKI-based authentication.
SV-268236r1137887_ruleThe HYCU virtual appliance must be configured to use at least two authentication servers for authenticating users prior to granting administration access.
SV-268237r1038754_ruleThe HYCU virtual appliance must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins.
SV-268238r1038665_ruleThe HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-268239r1038771_ruleThe HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to modify administrator privileges occur.
SV-268240r1038772_ruleThe HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to delete administrator privileges occur.
SV-268241r1038672_ruleThe HYCU virtual appliance must generate audit records when successful/unsuccessful login attempts occur.
SV-268242r1038675_ruleThe HYCU virtual appliance must generate audit records for privileged activities or other system-level access.
SV-268244r1211034_ruleThe HYCU virtual appliance must generate log records for a locally developed list of auditable events.
SV-268245r1038756_ruleThe HYCU virtual appliance must produce audit records containing information to establish when events occurred, where events occurred, the source of the event, the outcome of the event, and identity of any individual or process associated with the event.
SV-268246r1038438_ruleThe HYCU virtual appliance must generate audit records containing the full-text recording of privileged commands.
SV-268247r1038776_ruleThe HYCU virtual appliance must produce audit log records containing sufficient information to establish what type of event occurred.
SV-268248r1038777_ruleThe HYCU virtual appliance must initiate session auditing upon startup.
SV-268249r1038778_ruleThe HYCU virtual appliance must automatically audit account enabling actions.
SV-268250r1038779_ruleThe HYCU virtual appliance must generate audit records showing starting and ending time for administrator access to the system.
SV-268251r1038695_ruleThe HYCU virtual appliance must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-268252r1038698_ruleThe HYCU virtual appliance must support organizational requirements to conduct backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner.
SV-268253r1038701_ruleThe HYCU virtual appliance must off-load audit records onto a different system or media than the system being audited.
SV-268254r1038704_ruleThe HYCU virtual appliance must generate an immediate real-time alert of all audit failure events requiring real-time alerts.
SV-268255r1039643_ruleThe HYCU virtual appliance must protect audit information from unauthorized deletion.
SV-268256r1038708_ruleThe HYCU virtual appliance must protect audit tools from unauthorized access, modification, and deletion.
SV-268257r1207744_ruleThe HYCU virtual appliance must be running a release that is currently supported by the vendor.
SV-268258r1039645_ruleThe HYCU virtual appliance must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-268259r1043177_ruleThe HYCU virtual appliance must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.
SV-268260r1038716_ruleThe HYCU virtual appliance must implement replay-resistant authentication mechanisms for network access to privileged accounts.
SV-268262r1038718_ruleThe HYCU virtual appliance must enforce password complexity by requiring that at least one uppercase character be used.
SV-268263r1038720_ruleThe HYCU virtual appliance must enforce password complexity by requiring that at least one lowercase character be used.
SV-268264r1038722_ruleThe HYCU virtual appliance must enforce password complexity by requiring that at least one numeric character be used.
SV-268265r1038724_ruleThe HYCU virtual appliance must enforce password complexity by requiring that at least one special character be used.
SV-268266r1038758_ruleThe HYCU virtual appliance must enforce a minimum 15-character password length.
SV-268267r1043189_ruleThe HYCU virtual appliance must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
SV-268269r1038744_ruleThe HYCU virtual appliance must use FIPS 140-2-approved algorithms for authentication to a cryptographic module.
SV-268270r1038745_ruleThe HYCU virtual appliance must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.
SV-268271r1038746_ruleThe HYCU virtual appliance must be configured to implement cryptographic mechanisms using a FIPS 140-2-approved algorithm to protect the confidentiality of remote maintenance sessions.
SV-268274r1051115_ruleThe HYCU virtual appliance must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
SV-268282r1038736_ruleThe HYCU virtual appliance must audit the enforcement actions used to restrict access associated with changes to the device.
SV-268283r1038766_ruleThe HYCU virtual appliance must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
SV-268296r1137881_ruleThe HYCU virtual appliance must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
SV-268301r1195282_ruleThe HYCU virtual appliance must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.
SV-268302r1043181_ruleThe HYCU virtual appliance must generate unique session identifiers using a FIPS 140-2 approved random number generator.
SV-268303r1137890_ruleThe HYCU virtual appliance must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).