STIGQter STIGQter: STIG Summary:

NetApp ONTAP DSC 9.x Security Technical Implementation Guide

Version: 2

Release: 4 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-246922r1156802_ruleONTAP must be configured to limit the number of concurrent sessions.
SV-246923r1207671_ruleONTAP must be configured to create a session lock after 15 minutes.
SV-246925r961290_ruleONTAP must automatically audit account-enabling actions.
SV-246926r1051115_ruleONTAP must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
SV-246927r1137874_ruleONTAP must enforce administrator privileges based on their defined roles.
SV-246930r961353_ruleONTAP must prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-246931r960840_ruleONTAP must be configured to enforce the limit of three consecutive failed logon attempts.
SV-246932r960843_ruleONTAP must be configured to display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.
SV-246933r961392_ruleONTAP must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-246935r961401_ruleONTAP must have audit guarantee enabled.
SV-246936r1015268_ruleONTAP must be configured to synchronize internal information system clocks using redundant authoritative time sources.
SV-246938r961443_ruleONTAP must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
SV-246939r961461_ruleONTAP must enforce access restrictions associated with changes to the device configuration.
SV-246940r1211037_ruleONTAP must be configured to use an authentication server to provide multifactor authentication.
SV-246944r961863_ruleONTAP must be configured to conduct backups of system level information.
SV-246945r961863_ruleONTAP must use DoD-approved PKI rather than proprietary or self-signed device certificates.
SV-246946r1043177_ruleONTAP must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.
SV-246947r1015269_ruleONTAP must be configured to authenticate each administrator prior to authorizing privileges based on assignment of group or role.
SV-246948r1211039_ruleONTAP must implement replay-resistant authentication mechanisms for network access to privileged accounts.
SV-246949r961506_ruleONTAP must be configured to authenticate SNMP messages using FIPS-validated Keyed-HMAC.
SV-246950r961506_ruleONTAP must authenticate NTP sources using authentication that is cryptographically based.
SV-246951r1015270_ruleONTAP must enforce a minimum 15-character password length.
SV-246952r1015271_ruleONTAP must enforce password complexity by requiring that at least one uppercase character be used.
SV-246953r1015272_ruleONTAP must enforce password complexity by requiring that at least one lowercase character be used.
SV-246954r1015273_ruleONTAP must enforce password complexity by requiring that at least one numeric character be used.
SV-246955r1015274_ruleONTAP must enforce password complexity by requiring that at least one special character be used.
SV-246958r961557_ruleONTAP must be configured to implement cryptographic mechanisms using FIPS 140-2.
SV-246959r961068_ruleONTAP must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirements.
SV-246964r1137890_ruleONTAP must be configured to send audit log data to a central log server.