STIGQter STIGQter: STIG Summary:

Ivanti EPMM Server Security Technical Implementation Guide

Version: 3

Release: 1 Benchmark Date: 24 Oct 2024

CheckedNameTitle
SV-251400r1004719_ruleThe Ivanti EPMM server must limit the number of concurrent sessions per privileged user account to three or less concurrent sessions.
SV-251401r1004720_ruleThe Ivanti EPMM server must initiate a session lock after a 15-minute period of inactivity.
SV-251402r1004723_ruleThe Ivanti EPMM server must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-251403r1004724_ruleThe Ivanti EPMM server must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the application.
SV-251404r1004725_ruleThe Ivanti EPMM server must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
SV-251405r1004726_ruleThe Ivanti EPMM server must back up audit records at least every seven days onto a log management server.
SV-251406r1004727_ruleThe Ivanti EPMM server must be configured to use a DoD Central Directory Service to provide multifactor authentication for network access to privileged and non-privileged accounts.
SV-251407r1004728_ruleThe Ivanti EPMM server must enforce a minimum 15-character password length.
SV-251408r1004729_ruleThe Ivanti EPMM server must prohibit password reuse for a minimum of four generations.
SV-251409r1004730_ruleThe Ivanti EPMM server must enforce password complexity by requiring that at least one uppercase character be used.
SV-251410r1004731_ruleThe Ivanti EPMM server must enforce password complexity by requiring that at least one lowercase character be used.
SV-251411r1004732_ruleThe Ivanti EPMM server must enforce password complexity by requiring that at least one numeric character be used.
SV-251412r1004733_ruleThe Ivanti EPMM server must enforce password complexity by requiring that at least one special character be used.
SV-251413r1004734_ruleThe Ivanti EPMM server must use FIPS-validated SHA-2 or higher hash function to protect the integrity of keyed-hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, and hash-only applications.
SV-251414r1004735_ruleThe Ivanti EPMM server must automatically terminate a user session after an organization-defined period of user inactivity.
SV-251415r1004742_ruleThe Ivanti EPMM server must be configured to transfer Ivanti EPMM server logs to another server for storage, analysis, and reporting. Note: Ivanti EPMM server logs include logs of UEM events and logs transferred to the Ivanti EPMM server by UEM agents of managed devices.
SV-251416r1004743_ruleThe Ivanti EPMM server must configure web management tools with FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to protect the confidentiality of maintenance and diagnostic communications for nonlocal maintenance sessions.
SV-251417r1004744_ruleThe Ivanti EPMM server must only allow the use of DoD PKI established certificate authorities for verification of the establishment of protected sessions.
SV-251418r1004745_ruleThe Ivanti EPMM server must be maintained at a supported version.
SV-251419r1004746_ruleThe Ivanti EPMM server must be configured with the periodicity of the following commands to the agent of six hours or less: - query connectivity status - query the current version of the managed device firmware/software - query the current version of installed mobile applications - read audit logs kept by the managed device.
SV-251420r1004747_ruleThe Ivanti EPMM server must use a FIPS-validated cryptographic module to generate cryptographic hashes.
SV-251421r1004748_ruleThe Ivanti EPMM server must, at a minimum, off-load audit logs of interconnected systems in real time and off-load standalone systems weekly.
SV-251422r1004749_ruleThe Ivanti EPMM server must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs.
SV-251423r1004750_ruleThe Ivanti EPMM server must be configured to implement FIPS 140-2 mode for all server and agent encryption.
SV-251774r1004738_ruleThe Ivanti EPMM server must configured to lock administrator accounts after three unsuccessful login attempts.
SV-251777r1004741_ruleThe Ivanti EPMM server must be configured to lock an administrator's account for at least 15 minutes after the account has been locked because the maximum number of unsuccessful login attempts has been exceeded.