| Checked | Name | Title |
|---|
| ☐ | SV-281366r1186136_rule | TCMax must initiate a session lock after a 15-minute period of inactivity. |
| ☐ | SV-281367r1185141_rule | TCMax must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period. |
| ☐ | SV-281368r1185144_rule | TCMax must protect audit information from any type of unauthorized read access. |
| ☐ | SV-281369r1195319_rule | TCMax must be configured to prohibit or restrict using organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments. |
| ☐ | SV-281370r1186141_rule | TCMax must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). |
| ☐ | SV-281371r1186143_rule | TCMax must enforce a minimum 15-character password length. |
| ☐ | SV-281372r1186146_rule | TCMax must enforce password complexity by requiring that at least one uppercase letter, one lowercase letter, and number, and one special character be used. |
| ☐ | SV-281373r1186149_rule | TCMax must require the change of at least eight of the total number of characters when passwords are changed. |
| ☐ | SV-281374r1186152_rule | TCMax must enforce 24 hours/1 day as the minimum password lifetime. |
| ☐ | SV-281375r1186155_rule | TCMax must enforce a 60-day maximum password lifetime restriction. |
| ☐ | SV-281376r1195320_rule | TCMax must protect the confidentiality and integrity of transmitted information. |
| ☐ | SV-281377r1186158_rule | TCMax must accept personal identity verification (PIV) credentials. |
| ☐ | SV-281378r1195327_rule | TCMax must install security-relevant software updates within the time period directed by an authoritative source (e.g., IAVM, CTOs, DTMs, and STIGs). |
| ☐ | SV-281379r1186169_rule | For password-based authentication, TCMax must require immediate selection of a new password upon account recovery. |
| ☐ | SV-281380r1186164_rule | TCMax must enforce a role-based access control (RBAC) policy over defined subjects and objects. |
| ☐ | SV-281381r1186170_rule | TCMax must be running a version supported by the vendor. |
| ☐ | SV-281382r1186167_rule | TCMax must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). |