| Checked | Name | Title |
|---|
| ☐ | SV-251400r1004719_rule | The Ivanti EPMM server must limit the number of concurrent sessions per privileged user account to three or less concurrent sessions. |
| ☐ | SV-251401r1004720_rule | The Ivanti EPMM server must initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-251402r1004723_rule | The Ivanti EPMM server must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. |
| ☐ | SV-251403r1004724_rule | The Ivanti EPMM server must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the application. |
| ☐ | SV-251404r1004725_rule | The Ivanti EPMM server must alert the ISSO and SA (at a minimum) in the event of an audit processing failure. |
| ☐ | SV-251405r1004726_rule | The Ivanti EPMM server must back up audit records at least every seven days onto a log management server. |
| ☐ | SV-251406r1004727_rule | The Ivanti EPMM server must be configured to use a DoD Central Directory Service to provide multifactor authentication for network access to privileged and non-privileged accounts. |
| ☐ | SV-251407r1004728_rule | The Ivanti EPMM server must enforce a minimum 15-character password length. |
| ☐ | SV-251408r1004729_rule | The Ivanti EPMM server must prohibit password reuse for a minimum of four generations. |
| ☐ | SV-251409r1004730_rule | The Ivanti EPMM server must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-251410r1004731_rule | The Ivanti EPMM server must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-251411r1004732_rule | The Ivanti EPMM server must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-251412r1004733_rule | The Ivanti EPMM server must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-251413r1004734_rule | The Ivanti EPMM server must use FIPS-validated SHA-2 or higher hash function to protect the integrity of keyed-hash message authentication code (HMAC), Key Derivation Functions (KDFs), Random Bit Generation, and hash-only applications. |
| ☐ | SV-251414r1004735_rule | The Ivanti EPMM server must automatically terminate a user session after an organization-defined period of user inactivity. |
| ☐ | SV-251415r1004742_rule | The Ivanti EPMM server must be configured to transfer Ivanti EPMM server logs to another server for storage, analysis, and reporting. Note: Ivanti EPMM server logs include logs of UEM events and logs transferred to the Ivanti EPMM server by UEM agents of managed devices. |
| ☐ | SV-251416r1004743_rule | The Ivanti EPMM server must configure web management tools with FIPS-validated Advanced Encryption Standard (AES) cipher block algorithm to protect the confidentiality of maintenance and diagnostic communications for nonlocal maintenance sessions. |
| ☐ | SV-251417r1004744_rule | The Ivanti EPMM server must only allow the use of DoD PKI established certificate authorities for verification of the establishment of protected sessions. |
| ☐ | SV-251418r1004745_rule | The Ivanti EPMM server must be maintained at a supported version. |
| ☐ | SV-251419r1004746_rule | The Ivanti EPMM server must be configured with the periodicity of the following commands to the agent of six hours or less: - query connectivity status - query the current version of the managed device firmware/software - query the current version of installed mobile applications - read audit logs kept by the managed device. |
| ☐ | SV-251420r1004747_rule | The Ivanti EPMM server must use a FIPS-validated cryptographic module to generate cryptographic hashes. |
| ☐ | SV-251421r1004748_rule | The Ivanti EPMM server must, at a minimum, off-load audit logs of interconnected systems in real time and off-load standalone systems weekly. |
| ☐ | SV-251422r1004749_rule | The Ivanti EPMM server must be configured in accordance with the security configuration settings based on DoD security configuration or implementation guidance, including STIGs, NSA configuration guides, CTOs, and DTMs. |
| ☐ | SV-251423r1004750_rule | The Ivanti EPMM server must be configured to implement FIPS 140-2 mode for all server and agent encryption. |
| ☐ | SV-251774r1004738_rule | The Ivanti EPMM server must configured to lock administrator accounts after three unsuccessful login attempts. |
| ☐ | SV-251777r1004741_rule | The Ivanti EPMM server must be configured to lock an administrator's account for at least 15 minutes after the account has been locked because the maximum number of unsuccessful login attempts has been exceeded. |