| Checked | Name | Title |
|---|
| ☐ | SV-258598r1028331_rule | The ICS must be configured to implement cryptographic mechanisms using a FIPS 140-2/140-3 approved algorithm. |
| ☐ | SV-258599r961863_rule | The ICS must be configured to send admin log data to a redundant central log server. |
| ☐ | SV-258600r997506_rule | The ICS must be configured to prevent nonprivileged users from executing privileged functions. |
| ☐ | SV-258601r997507_rule | The ICS must be configured to audit the execution of privileged functions such as accounts additions and changes. |
| ☐ | SV-258602r961506_rule | If SNMP is used, the ICS must be configured to use SNMPv3 with FIPS-140-2/3 validated Keyed-Hash Message Authentication Code (HMAC). |
| ☐ | SV-258603r961506_rule | The ICS must be configured to authenticate Network Time Protocol (NTP) sources using authentication that is cryptographically based. |
| ☐ | SV-258604r961443_rule | The ICS must be configured to record time stamps for audit records that can be mapped to Greenwich Mean Time (GMT). |
| ☐ | SV-258605r961392_rule | The ICS must be configured to allocate local audit record storage capacity in accordance with organization-defined audit record storage requirements. |
| ☐ | SV-258606r997508_rule | The ICS must be configured to enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-258607r1051115_rule | The ICS must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable. |
| ☐ | SV-258608r1136931_rule | The ICS must be configured to terminate after five minutes of inactivity except to fulfill documented and validated mission requirements. |
| ☐ | SV-258609r1007840_rule | The ICS must be configured to use DOD PKI as multifactor authentication (MFA) for interactive logins. |
| ☐ | SV-258610r997509_rule | The ICS must be configured to synchronize internal information system clocks using redundant authoritative time sources. |
| ☐ | SV-258611r961863_rule | The ICS must be configured to obtain its public key certificates from an appropriate certificate policy through an approved service provider. |
| ☐ | SV-258612r961863_rule | The ICS must be configured to support organizational requirements to conduct weekly backups of information system documentation, including security-related documentation. |
| ☐ | SV-258613r961863_rule | The ICS must be configured to run an operating system release that is currently supported by Ivanti. |
| ☐ | SV-258614r997510_rule | The ICS must be configured to enforce a minimum 15-character password length. |
| ☐ | SV-258615r961029_rule | The ICS must be configured to transmit only encrypted representations of passwords. |
| ☐ | SV-258616r1043189_rule | The ICS must be configured to require that when a password is changed, the characters are changed in at least eight of the positions within the password. |
| ☐ | SV-258617r997512_rule | The ICS must be configured to enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-258618r997513_rule | The ICS must be configured to enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-258619r997514_rule | The ICS must be configured to enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-258620r997515_rule | The ICS must be configured to use DOD approved OCSP responders or CRLs to validate certificates used for PKI-based authentication. |
| ☐ | SV-258621r960885_rule | The ICS must be configured to generate audit records when successful/unsuccessful attempts to access privileges occur. |
| ☐ | SV-258622r960735_rule | The ICS must be configured to limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type. |
| ☐ | SV-258623r960843_rule | The ICS must be configured to display the Standard Mandatory DOD Notice and Consent Banner before granting access to manage the device. |
| ☐ | SV-258624r960840_rule | The ICS must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes. |
| ☐ | SV-258625r961863_rule | The ICS must be configured to conduct backups of system level information contained in the information system when changes occur. |
| ☐ | SV-268324r1136874_rule | The ICS must be configured to protect against known types of denial-of-service (DoS) attacks by enabling JITC mode. |