| Checked | Name | Title |
|---|
| ☐ | SV-224760r1013798_rule | The ISEC7 SPHERE must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types. |
| ☐ | SV-224761r1013800_rule | The ISEC7 SPHERE must initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-224762r1013803_rule | The ISEC7 SPHERE must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access. |
| ☐ | SV-224763r1013805_rule | The ISEC7 SPHERE must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the ISEC7 SPHERE. |
| ☐ | SV-224764r1013808_rule | The ISEC7 SPHERE server must be configured to have at least one user in the following Administrator roles: Security Administrator, Site Administrator, and Help Desk User. |
| ☐ | SV-224765r1013811_rule | The ISEC7 SPHERE must alert the information system security officer (ISSO) and system administrator (SA) (at a minimum) in the event of an audit processing failure. |
| ☐ | SV-224766r1013812_rule | The ISEC7 SPHERE must back up audit records at least every seven days onto a different system or system component than the system or component being audited, provide centralized management and configuration of the content to be captured in audit records generated by all ISEC7 SPHERE components, and offload audit records onto a different system or media than the system being audited. |
| ☐ | SV-224767r1013815_rule | ISEC7 SPHERE must disable or delete local account created during application installation and configuration. |
| ☐ | SV-224768r1013818_rule | When using PKI-based authentication for user access, the ISEC7 SPHERE must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor. |
| ☐ | SV-224769r1013821_rule | The ISEC7 SPHERE must accept Personal Identity Verification (PIV) credentials. |
| ☐ | SV-224770r1013824_rule | Before establishing a local, remote, and/or network connection with any endpoint device, the ISEC7 SPHERE must use a bidirectional authentication mechanism configured with a FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to authenticate with the device. |
| ☐ | SV-224771r1013827_rule | The ISEC7 SPHERE must allow the use of DOD PKI established certificate authorities for verification of the establishment of protected sessions. |
| ☐ | SV-224772r1013830_rule | The ISEC7 SPHERE must protect the confidentiality and integrity of transmitted information during preparation for transmission and during reception using cryptographic mechanisms. |
| ☐ | SV-224773r1013833_rule | The ISEC7 SPHERE must be configured to leverage the enterprise directory service accounts and groups for ISEC7 SPHERE server admin identification and authentication. |
| ☐ | SV-224774r1013835_rule | The ISEC7 SPHERE must configure the timeout for the console to be 15 minutes or less. |
| ☐ | SV-224775r1013838_rule | The ISEC7 SPHERE, Tomcat installation, and ISEC7 Suite monitor must be configured to use the Windows Trust Store for the storage of digital certificates and keys. |
| ☐ | SV-224776r1013841_rule | If cipher suites using pre-shared keys are used for device authentication, the ISEC7 SPHERE must have a minimum security strength of 112 bits or higher, must only be used in networks where both the client and server are government systems, must prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0 and must prohibit or restrict the use of protocols that transmit unencrypted authentication information or use flawed cryptographic algorithm for transmission. |
| ☐ | SV-224777r1013844_rule | The ISEC7 SPHERE must use FIPS-validated SHA-2 or higher hash function for digital signature generation and verification (nonlegacy use). |
| ☐ | SV-224778r1013847_rule | The ISEC7 SPHERE must use a FIPS-validated cryptographic module to provision digital signatures. |
| ☐ | SV-224779r1013850_rule | The ISEC7 SPHERE must use a FIPS 140-2-validated cryptographic module to implement encryption services for unclassified information requiring confidentiality, generate cryptographic hashes, and to configure web management tools with FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to protect the confidentiality of maintenance and diagnostic communications for nonlocal maintenance sessions. |
| ☐ | SV-224780r1013853_rule | The Apache Tomcat Manager Web app password must be cryptographically hashed with a DOD-approved algorithm. |
| ☐ | SV-224781r1013855_rule | All Web applications included with Apache Tomcat that are not required must be removed. |
| ☐ | SV-224782r1013858_rule | LockOutRealm must not be removed from Apache Tomcat. |
| ☐ | SV-224783r1013861_rule | The LockOutRealm must be configured with a login failure count of 3. |
| ☐ | SV-224784r1013864_rule | The LockOutRealm must be configured with a login lockout time of 15 minutes. |
| ☐ | SV-224785r1013867_rule | The Manager Web app password must be configured as follows:
-15 or more characters.
-at least one lower case letter.
-at least one upper case letter.
-at least one number.
-at least one special character. |
| ☐ | SV-224786r1013870_rule | The ISEC7 SPHERE must configure Enable HTTPS to use HTTP over SSL in Apache Tomcat. |
| ☐ | SV-224788r1013873_rule | Stack tracing must be disabled in Apache Tomcat. |
| ☐ | SV-224789r1013876_rule | The Apache Tomcat shutdown port must be disabled. |
| ☐ | SV-224790r1013879_rule | The ISEC7 SPHERE must remove any unnecessary users or groups that have permissions to the server.xml file in Apache Tomcat. |
| ☐ | SV-224791r1013882_rule | A manager role must be assigned to the Apache Tomcat Web apps (Manager, Host-Manager). |
| ☐ | SV-224792r1013885_rule | SSL must be enabled on Apache Tomcat. |
| ☐ | SV-224793r1013888_rule | Tomcat SSL must be restricted except for ISEC7 SPHERE tasks. |
| ☐ | SV-225096r1013891_rule | The ISEC7 Sphere server must be maintained at a supported version. |