| Checked | Name | Title |
|---|
| ☐ | SV-254086r845234_rule | Innoslate must initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-254087r845265_rule | Innoslate must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination using remote access. |
| ☐ | SV-254088r845240_rule | Innoslate must provide automated mechanisms for supporting account management functions. |
| ☐ | SV-254089r845243_rule | Innoslate must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
| ☐ | SV-254090r845246_rule | Innoslate must enforce approved authorizations for controlling the flow of information within the system based on organization-defined information flow control policies. |
| ☐ | SV-254091r845249_rule | The publicly accessible application must display the Standard Mandatory DoD Notice and Consent Banner before granting access to Innoslate. |
| ☐ | SV-254092r845252_rule | Innoslate must generate comprehensive audit records. |
| ☐ | SV-254093r845255_rule | Innoslate must use multifactor authentication for network access to privileged and non-privileged accounts. |
| ☐ | SV-254094r845258_rule | Innoslate must map the authenticated identity to the individual user or group account for PKI-based authentication. |
| ☐ | SV-254095r845261_rule | Innoslate must off-load audit records onto a different system or media than the system being audited. |
| ☐ | SV-254096r845264_rule | Innoslate must generate audit records when DoD required events occur. |