| Checked | Name | Title |
|---|
| ☐ | SV-268216r1038348_rule | The HYCU virtual appliance must be configured to synchronize internal information system clocks using redundant authoritative time sources. |
| ☐ | SV-268217r1067634_rule | The HYCU virtual appliance must not have any default manufacturer passwords when deployed. |
| ☐ | SV-268219r1038638_rule | The HYCU virtual appliance must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type. |
| ☐ | SV-268222r1137874_rule | The HYCU virtual appliance must enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level in accordance with applicable policy for the device. |
| ☐ | SV-268223r1137878_rule | If the HYCU virtual appliance uses role-based access control, it must enforce organization-defined role-based access control policies over defined subjects and objects. |
| ☐ | SV-268225r1137875_rule | The HYCU virtual appliance must enforce approved authorizations for controlling the flow of management information within the appliance based on information flow control policies. |
| ☐ | SV-268226r1038378_rule | The HYCU virtual appliance must audit the execution of privileged functions. |
| ☐ | SV-268227r1038750_rule | The HYCU virtual appliance must be configured to enforce the limit of three consecutive invalid login attempts, after which time it must block any login attempt for 15 minutes. |
| ☐ | SV-268228r1038752_rule | The HYCU virtual appliance must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device. |
| ☐ | SV-268229r1038748_rule | The HYCU virtual appliance must retain the Standard Mandatory DOD Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log in for further access. |
| ☐ | SV-268231r1038648_rule | The HYCU virtual appliance must automatically audit account creation. |
| ☐ | SV-268232r1038650_rule | The HYCU virtual appliance must automatically audit account modification. |
| ☐ | SV-268233r1038652_rule | The HYCU virtual appliance must automatically audit account disabling actions. |
| ☐ | SV-268234r1038654_rule | The HYCU virtual appliance must automatically audit account removal actions. |
| ☐ | SV-268235r1038742_rule | The HYCU virtual appliance must be configured to use DOD-approved online certificate status protocol (OCSP) responders or certificate revocation lists (CRLs) to validate certificates used for PKI-based authentication. |
| ☐ | SV-268236r1137887_rule | The HYCU virtual appliance must be configured to use at least two authentication servers for authenticating users prior to granting administration access. |
| ☐ | SV-268237r1038754_rule | The HYCU virtual appliance must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins. |
| ☐ | SV-268238r1038665_rule | The HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to access privileges occur. |
| ☐ | SV-268239r1038771_rule | The HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to modify administrator privileges occur. |
| ☐ | SV-268240r1038772_rule | The HYCU virtual appliance must generate audit records when successful/unsuccessful attempts to delete administrator privileges occur. |
| ☐ | SV-268241r1038672_rule | The HYCU virtual appliance must generate audit records when successful/unsuccessful login attempts occur. |
| ☐ | SV-268242r1038675_rule | The HYCU virtual appliance must generate audit records for privileged activities or other system-level access. |
| ☐ | SV-268244r1211034_rule | The HYCU virtual appliance must generate log records for a locally developed list of auditable events. |
| ☐ | SV-268245r1038756_rule | The HYCU virtual appliance must produce audit records containing information to establish when events occurred, where events occurred, the source of the event, the outcome of the event, and identity of any individual or process associated with the event. |
| ☐ | SV-268246r1038438_rule | The HYCU virtual appliance must generate audit records containing the full-text recording of privileged commands. |
| ☐ | SV-268247r1038776_rule | The HYCU virtual appliance must produce audit log records containing sufficient information to establish what type of event occurred. |
| ☐ | SV-268248r1038777_rule | The HYCU virtual appliance must initiate session auditing upon startup. |
| ☐ | SV-268249r1038778_rule | The HYCU virtual appliance must automatically audit account enabling actions. |
| ☐ | SV-268250r1038779_rule | The HYCU virtual appliance must generate audit records showing starting and ending time for administrator access to the system. |
| ☐ | SV-268251r1038695_rule | The HYCU virtual appliance must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements. |
| ☐ | SV-268252r1038698_rule | The HYCU virtual appliance must support organizational requirements to conduct backups of information system documentation, including security-related documentation, when changes occur or weekly, whichever is sooner. |
| ☐ | SV-268253r1038701_rule | The HYCU virtual appliance must off-load audit records onto a different system or media than the system being audited. |
| ☐ | SV-268254r1038704_rule | The HYCU virtual appliance must generate an immediate real-time alert of all audit failure events requiring real-time alerts. |
| ☐ | SV-268255r1039643_rule | The HYCU virtual appliance must protect audit information from unauthorized deletion. |
| ☐ | SV-268256r1038708_rule | The HYCU virtual appliance must protect audit tools from unauthorized access, modification, and deletion. |
| ☐ | SV-268257r1207744_rule | The HYCU virtual appliance must be running a release that is currently supported by the vendor. |
| ☐ | SV-268258r1039645_rule | The HYCU virtual appliance must obtain its public key certificates from an appropriate certificate policy through an approved service provider. |
| ☐ | SV-268259r1043177_rule | The HYCU virtual appliance must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services. |
| ☐ | SV-268260r1038716_rule | The HYCU virtual appliance must implement replay-resistant authentication mechanisms for network access to privileged accounts. |
| ☐ | SV-268262r1038718_rule | The HYCU virtual appliance must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-268263r1038720_rule | The HYCU virtual appliance must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-268264r1038722_rule | The HYCU virtual appliance must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-268265r1038724_rule | The HYCU virtual appliance must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-268266r1038758_rule | The HYCU virtual appliance must enforce a minimum 15-character password length. |
| ☐ | SV-268267r1043189_rule | The HYCU virtual appliance must require that when a password is changed, the characters are changed in at least eight of the positions within the password. |
| ☐ | SV-268269r1038744_rule | The HYCU virtual appliance must use FIPS 140-2-approved algorithms for authentication to a cryptographic module. |
| ☐ | SV-268270r1038745_rule | The HYCU virtual appliance must use FIPS-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications. |
| ☐ | SV-268271r1038746_rule | The HYCU virtual appliance must be configured to implement cryptographic mechanisms using a FIPS 140-2-approved algorithm to protect the confidentiality of remote maintenance sessions. |
| ☐ | SV-268274r1051115_rule | The HYCU virtual appliance must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable. |
| ☐ | SV-268282r1038736_rule | The HYCU virtual appliance must audit the enforcement actions used to restrict access associated with changes to the device. |
| ☐ | SV-268283r1038766_rule | The HYCU virtual appliance must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization. |
| ☐ | SV-268296r1137881_rule | The HYCU virtual appliance must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs). |
| ☐ | SV-268301r1195282_rule | The HYCU virtual appliance must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements. |
| ☐ | SV-268302r1043181_rule | The HYCU virtual appliance must generate unique session identifiers using a FIPS 140-2 approved random number generator. |
| ☐ | SV-268303r1137890_rule | The HYCU virtual appliance must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO). |