| Checked | Name | Title |
|---|
| ☐ | SV-273186r1098825_rule | Okta must log out a session after a 15-minute period of inactivity. |
| ☐ | SV-273187r1098828_rule | The Okta Admin Console must log out a session after a 15-minute period of inactivity. |
| ☐ | SV-273188r1098831_rule | Okta must automatically disable accounts after a 35-day period of account inactivity. |
| ☐ | SV-273189r1098834_rule | Okta must enforce the limit of three consecutive invalid login attempts by a user during a 15-minute time period. |
| ☐ | SV-273190r1099763_rule | The Okta Dashboard application must be configured to allow authentication only via non-phishable authenticators. |
| ☐ | SV-273191r1099764_rule | The Okta Admin Console application must be configured to allow authentication only via non-phishable authenticators. |
| ☐ | SV-273192r1098843_rule | Okta must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the application. |
| ☐ | SV-273193r1098846_rule | The Okta Admin Console application must be configured to use multifactor authentication. |
| ☐ | SV-273194r1098849_rule | The Okta Dashboard application must be configured to use multifactor authentication. |
| ☐ | SV-273195r1098852_rule | Okta must enforce a minimum 15-character password length. |
| ☐ | SV-273196r1098855_rule | Okta must enforce password complexity by requiring that at least one uppercase character be used. |
| ☐ | SV-273197r1098858_rule | Okta must enforce password complexity by requiring that at least one lowercase character be used. |
| ☐ | SV-273198r1098861_rule | Okta must enforce password complexity by requiring that at least one numeric character be used. |
| ☐ | SV-273199r1098864_rule | Okta must enforce password complexity by requiring that at least one special character be used. |
| ☐ | SV-273200r1098867_rule | Okta must enforce 24 hours/one day as the minimum password lifetime. |
| ☐ | SV-273201r1098870_rule | Okta must enforce a 60-day maximum password lifetime restriction. |
| ☐ | SV-273202r1099766_rule | Okta must off-load audit records onto a central log server. |
| ☐ | SV-273203r1099958_rule | Okta must be configured to limit the global session lifetime to 18 hours. |
| ☐ | SV-273204r1098879_rule | Okta must be configured to accept Personal Identity Verification (PIV) credentials. |
| ☐ | SV-273205r1098882_rule | The Okta Verify application must be configured to connect only to FIPS-compliant devices. |
| ☐ | SV-273206r1098885_rule | Okta must be configured to disable persistent global session cookies. |
| ☐ | SV-273207r1098888_rule | Okta must be configured to use only DOD-approved certificate authorities. |
| ☐ | SV-273208r1099769_rule | Okta must validate passwords against a list of commonly used, expected, or compromised passwords. |
| ☐ | SV-273209r1098894_rule | Okta must prohibit password reuse for a minimum of five generations. |
| ☐ | SV-279689r1155066_rule | Okta API tokens must be configured with Network Zones to restrict authorization from known networks. |
| ☐ | SV-279690r1155069_rule | Okta API tokens must be created under new dedicated user accounts. |
| ☐ | SV-279691r1155072_rule | The Okta Global Session policy must be configured to allow or deny IP based access in accordance with the Access Control policy for Okta. |
| ☐ | SV-279692r1155075_rule | Okta must be configured with Network Zones defined to block anonymized proxies according to organizationally defined policy. |
| ☐ | SV-279693r1155078_rule | For each application integrated with Okta, network zones must be defined in its authentication policy. |