| Checked | Name | Title |
|---|
| ☐ | SV-250982r1028209_rule | Sentry must limit the number of concurrent sessions for the CLISH interface to an organization-defined number for each administrator account and/or administrator account type. |
| ☐ | SV-250983r1028210_rule | Sentry must be configured to limit the network access of the Sentry System Manager Portal behind the corporate firewall and whitelist source IP range. |
| ☐ | SV-250984r1028211_rule | Sentry must initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-250985r1028212_rule | Sentry must enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies. |
| ☐ | SV-250986r1028213_rule | Sentry must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes. |
| ☐ | SV-250987r1028214_rule | Sentry must display the Standard Mandatory DOD Notice and Consent Banner in the Sentry web interface before granting access to the device. |
| ☐ | SV-250988r1028216_rule | Sentry must be configured to use DOD PKI as multi-factor authentication (MFA) for interactive logins. |
| ☐ | SV-250989r1029559_rule | Sentry device must enforce a minimum 15-character password length. |
| ☐ | SV-250990r1029560_rule | Sentry must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-250991r1029561_rule | Sentry must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-250992r1029562_rule | Sentry must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-250993r1029563_rule | Sentry must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-250994r1028230_rule | Sentry, for PKI-based authentication, must be configured to map validated certificates to unique user accounts. |
| ☐ | SV-250995r1028232_rule | Sentry must use FIPS 140-2 approved algorithms for authentication to a cryptographic module. |
| ☐ | SV-250996r1028233_rule | Sentry must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirement. |
| ☐ | SV-250997r1028235_rule | Sentry must generate unique session identifiers using a FIPS 140-2 approved random number generator. |
| ☐ | SV-250998r1028236_rule | Sentry must generate an immediate real-time alert of all audit failure events requiring real-time alerts. |
| ☐ | SV-250999r1029564_rule | Sentry must be configured to synchronize internal information system clocks using redundant authoritative time sources. |
| ☐ | SV-251000r1028238_rule | The Sentry must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC). |
| ☐ | SV-251001r1028239_rule | Sentry must be configured to implement cryptographic mechanisms using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions. |
| ☐ | SV-251002r1028240_rule | Sentry must offload audit records onto a different system or media than the system being audited. |
| ☐ | SV-251003r1028241_rule | Sentry must enforce access restrictions associated with changes to the system components. |
| ☐ | SV-251004r1028242_rule | Sentry must be configured to conduct backups of system level information contained in the information system when changes occur. |
| ☐ | SV-251005r1028243_rule | Sentry must obtain its public key certificates from an appropriate certificate policy through an approved service provider. |
| ☐ | SV-251006r1028244_rule | Sentry must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the ISSO. |
| ☐ | SV-251007r1028245_rule | Sentry must be running an operating system release that is currently supported by MobileIron. |