STIGQter STIGQter: STIG Summary:

Symantec Edge SWG ALG Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 25 Nov 2025

CheckedNameTitle
SV-279166r1170654_ruleThe ALG providing user authentication intermediary services must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users).
SV-279167r1170656_ruleThe Edge SWG must implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
SV-279168r1170614_ruleThe Edge SWG must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
SV-279175r1170658_ruleThe Edge SWG must display the standard mandatory DOD-approved notice and consent banner before granting access to the network.
SV-279176r1170660_ruleThe Edge SWG must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
SV-279177r1170662_ruleThe Edge SWG must ensure inbound and outbound traffic is monitored for compliance with remote access security policies.
SV-279178r1170664_ruleThe Edge SWG must be configured to comply with the required TLS settings in NIST SP 800-52.
SV-279180r1170629_ruleThe Edge SWG must be configured to remove or disable unrelated or unneeded application proxy services.
SV-279187r1170651_ruleIn the event of a system failure of the ALG function, the Edge SWG must save diagnostic information, log system messages, and load the most current security policies, rules, and signatures when restarted.
SV-279194r1170667_ruleThe Edge SWG must generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-279203r1170670_ruleThe Edge SWG must control remote access methods.
SV-279216r1170672_ruleThe Edge SWG providing user authentication intermediary services must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
SV-279217r1170674_ruleThe Edge SWG using PKI-based user authentication must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.
SV-279219r1170647_ruleThe Edge must implement load balancing to limit the effects of known and unknown types of denial-of-service (DoS) attacks.
SV-279222r1170676_ruleThe Edge SWG must fail securely in the event of an operational failure.