| Checked | Name | Title |
|---|
| ☐ | SV-284249r1223990_rule | The Omnissa WS1 UEM server must limit the number of concurrent sessions per privileged user account to three or less concurrent sessions. |
| ☐ | SV-284251r1223992_rule | The Omnissa WS1 UEM server must initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-284254r1223995_rule | The Omnissa WS1 UEM server must be configured to use a directory service for centralized account management. |
| ☐ | SV-284260r1224001_rule | The Omnissa WS1 UEM server must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. |
| ☐ | SV-284275r1224016_rule | The UEM SRG must alert the information system security officer and system administrator (at a minimum) in the event of an audit processing failure. |
| ☐ | SV-284282r1224025_rule | The firewall protecting the Omnissa WS1 UEM server platform must be configured so only DoW-approved ports, protocols, and services are enabled. (Refer to the DoW Ports, Protocols, Services Management [PPSM] Category Assurance Levels [CAL] list for DoW-approved ports, protocols, and services). |
| ☐ | SV-284284r1224027_rule | The Omnissa WS1 UEM server must be configured to require a One-Time Password (OTP) or Short Message Service (SMS) two-factor authentication for local accounts. |
| ☐ | SV-284305r1224048_rule | The Omnissa WS1 UEM server must be configured to transfer Omnissa WS1 UEM server logs to another server for storage, analysis, and reporting.
Note: Omnissa WS1 UEM server logs include logs of UEM events and logs transferred to the Omnissa WS1 UEM server by UEM agents of managed devices. |
| ☐ | SV-284306r1224049_rule | The Omnissa WS1 UEM server must be configured to record time stamps for audit records in Coordinated Universal Time (UTC). |
| ☐ | SV-284320r1224063_rule | The Omnissa WS1 UEM server must be configured with the periodicity of the following commands to the agent of six hours or less:
- Query connectivity status.
- Query the current version of the managed device firmware/software.
- Query the current version of installed mobile applications.
- Read audit logs kept by the managed device. |
| ☐ | SV-284349r1224092_rule | The Omnissa WS1 UEM server must enforce a minimum 15-character password length. |
| ☐ | SV-284350r1224093_rule | The Omnissa WS1 UEM server must prohibit password reuse for a minimum of five generations. |
| ☐ | SV-284351r1224094_rule | The Omnissa WS1 UEM server must enforce password complexity by requiring at least one uppercase character to be used. |
| ☐ | SV-284354r1224097_rule | The Omnissa WS1 UEM server must enforce a 60-day maximum password lifetime restriction. |
| ☐ | SV-284358r1224101_rule | The Omnissa WS1 UEM server must be configured to have at least one user in defined administrator roles. |