STIGQter STIGQter: STIG Summary:

Soaring Software Solutions TCMax 9.x Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 26 Feb 2026

CheckedNameTitle
SV-281366r1186136_ruleTCMax must initiate a session lock after a 15-minute period of inactivity.
SV-281367r1185141_ruleTCMax must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
SV-281368r1185144_ruleTCMax must protect audit information from any type of unauthorized read access.
SV-281369r1195319_ruleTCMax must be configured to prohibit or restrict using organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.
SV-281370r1186141_ruleTCMax must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-281371r1186143_ruleTCMax must enforce a minimum 15-character password length.
SV-281372r1186146_ruleTCMax must enforce password complexity by requiring that at least one uppercase letter, one lowercase letter, and number, and one special character be used.
SV-281373r1186149_ruleTCMax must require the change of at least eight of the total number of characters when passwords are changed.
SV-281374r1186152_ruleTCMax must enforce 24 hours/1 day as the minimum password lifetime.
SV-281375r1186155_ruleTCMax must enforce a 60-day maximum password lifetime restriction.
SV-281376r1195320_ruleTCMax must protect the confidentiality and integrity of transmitted information.
SV-281377r1186158_ruleTCMax must accept personal identity verification (PIV) credentials.
SV-281378r1195327_ruleTCMax must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs).
SV-281379r1186169_ruleFor password-based authentication, TCMax must require immediate selection of a new password upon account recovery.
SV-281380r1186164_ruleTCMax must enforce a role-based access control (RBAC) policy over defined subjects and objects.
SV-281381r1186170_ruleTCMax must be running a version supported by the vendor.
SV-281382r1186167_ruleTCMax must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).