STIGQter STIGQter: STIG Summary:

Omnissa WS1 UEM Server Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 26 May 2026

CheckedNameTitle
SV-284249r1223990_ruleThe Omnissa WS1 UEM server must limit the number of concurrent sessions per privileged user account to three or less concurrent sessions.
SV-284251r1223992_ruleThe Omnissa WS1 UEM server must initiate a session lock after a 15-minute period of inactivity.
SV-284254r1223995_ruleThe Omnissa WS1 UEM server must be configured to use a directory service for centralized account management.
SV-284260r1224001_ruleThe Omnissa WS1 UEM server must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-284275r1224016_ruleThe UEM SRG must alert the information system security officer and system administrator (at a minimum) in the event of an audit processing failure.
SV-284282r1224025_ruleThe firewall protecting the Omnissa WS1 UEM server platform must be configured so only DoW-approved ports, protocols, and services are enabled. (Refer to the DoW Ports, Protocols, Services Management [PPSM] Category Assurance Levels [CAL] list for DoW-approved ports, protocols, and services).
SV-284284r1224027_ruleThe Omnissa WS1 UEM server must be configured to require a One-Time Password (OTP) or Short Message Service (SMS) two-factor authentication for local accounts.
SV-284305r1224048_ruleThe Omnissa WS1 UEM server must be configured to transfer Omnissa WS1 UEM server logs to another server for storage, analysis, and reporting. Note: Omnissa WS1 UEM server logs include logs of UEM events and logs transferred to the Omnissa WS1 UEM server by UEM agents of managed devices.
SV-284306r1224049_ruleThe Omnissa WS1 UEM server must be configured to record time stamps for audit records in Coordinated Universal Time (UTC).
SV-284320r1224063_ruleThe Omnissa WS1 UEM server must be configured with the periodicity of the following commands to the agent of six hours or less: - Query connectivity status. - Query the current version of the managed device firmware/software. - Query the current version of installed mobile applications. - Read audit logs kept by the managed device.
SV-284349r1224092_ruleThe Omnissa WS1 UEM server must enforce a minimum 15-character password length.
SV-284350r1224093_ruleThe Omnissa WS1 UEM server must prohibit password reuse for a minimum of five generations.
SV-284351r1224094_ruleThe Omnissa WS1 UEM server must enforce password complexity by requiring at least one uppercase character to be used.
SV-284354r1224097_ruleThe Omnissa WS1 UEM server must enforce a 60-day maximum password lifetime restriction.
SV-284358r1224101_ruleThe Omnissa WS1 UEM server must be configured to have at least one user in defined administrator roles.