STIGQter STIGQter: STIG Summary:

Nokia Service Router OS 25.x Network Device Management Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 28 Apr 2026

CheckedNameTitle
SV-283760r1203325_ruleThe Nokia router must limit the number of concurrent management sessions to a maximum of three for each administrator account and/or administrator account type.
SV-283761r1223367_ruleThe Nokia router must be configured to assign appropriate user roles or access levels to authenticated users.
SV-283762r1203331_ruleThe Nokia router must enforce approved authorizations for controlling the flow of management information within the network device based on information flow control policies.
SV-283763r1203595_ruleThe Nokia router must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes.
SV-283764r1223368_ruleThe Nokia router must display the Standard Mandatory DoW Notice and Consent Banner before granting access to the device, and it must remain until the administrator acknowledges the usage conditions and takes explicit action to log on for further access.
SV-283765r1203340_ruleThe Nokia router must initiate session auditing upon startup.
SV-283766r1203597_ruleThe Nokia router must protect audit information from unauthorized modification.
SV-283767r1223369_ruleThe Nokia router must prevent the installation of patches, service packs, or application components without verification the software component has been digitally signed using a certificate that is recognized and approved by the organization.
SV-283768r1203574_ruleThe Nokia router must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services.
SV-283769r1203576_ruleThe Nokia router must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable.
SV-283770r1203355_ruleThe Nokia router must enforce a minimum 15-character password length.
SV-283771r1203358_ruleThe Nokia router must enforce password complexity.
SV-283772r1203361_ruleThe Nokia router must require that when a password is changed, the characters are changed in at least eight of the positions within the password.
SV-283773r1203364_ruleThe Nokia router must only store cryptographic representations of passwords.
SV-283774r1223370_ruleThe Nokia router must use Federal Information Processing Standard (FIPS) 140-3-approved algorithms for authentication to a cryptographic module.
SV-283775r1203370_ruleThe Nokia router must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements.
SV-283776r1203373_ruleThe Nokia router must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-283777r1203376_ruleThe Nokia router must generate an immediate real-time alert for all audit failure events requiring real-time alerts.
SV-283778r1203581_ruleThe Nokia router must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).
SV-283779r1203583_ruleThe Nokia router must record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.
SV-283780r1203385_ruleThe Nokia router must be configured to authenticate Simple Network Management Protocol (SNMP) messages using a Federal Information Processing Standard (FIPS)-validated Keyed-Hash message authentication code.
SV-283781r1203388_ruleThe Nokia router must be configured to authenticate Network Time Protocol (NTP) sources using authentication with a Federal Information Processing Standard (FIPS)-compliant algorithm.
SV-283782r1223371_ruleThe Nokia router must use Federal Information Processing Standard (FIPS)-validated Keyed-Hash Message Authentication Code (HMAC) to protect the integrity of nonlocal maintenance and diagnostic communications.
SV-283783r1223372_ruleThe Nokia router must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards.
SV-283784r1203397_ruleThe Nokia router must off-load audit records onto a different system or media than the system being audited.
SV-283785r1203604_ruleThe Nokia router must be configured to use at least two authentication servers for authenticating users prior to granting administrative access.
SV-283786r1203403_ruleThe Nokia router must be configured to conduct backups of system-level information contained in the information system when changes occur.
SV-283787r1203406_ruleThe Nokia router must obtain its public key certificates from an appropriate certificate policy through an approved service provider.
SV-283788r1203409_ruleThe Nokia router must be configured to send log data to at least two central log servers for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO).
SV-283789r1207744_ruleThe Nokia router must be running an operating system release that is currently supported by the vendor.
SV-283790r1203415_ruleThe Nokia router must be configured to alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information.
SV-283791r1203418_ruleThe Nokia router must be configured to implement a local cache of revocation data to support path discovery and validation for public key-based authentication.
SV-283792r1203421_ruleThe Nokia router must be configured to protect nonlocal maintenance sessions by separating the maintenance session from other network sessions within the system by logically separated communications paths.
SV-283793r1203590_ruleThe Nokia router must be configured to include only approved trust anchors in trust stores or certificate stores managed by the organization.
SV-283794r1203427_ruleThe Nokia router must be configured to synchronize system clocks within and between systems or system components.
SV-283795r1203430_ruleThe Nokia router must be configured to compare the internal system clocks on an organization-defined frequency with an organization-defined authoritative time source.
SV-283799r1203603_ruleThe Nokia router must be configured to implement multifactor authentication for local, network, and/or remote access to privileged and nonprivileged accounts such that the device meets organization-defined strength of mechanism requirements.