| Checked | Name | Title |
|---|
| ☐ | SV-279166r1170654_rule | The ALG providing user authentication intermediary services must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users). |
| ☐ | SV-279167r1170656_rule | The Edge SWG must implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access. |
| ☐ | SV-279168r1170614_rule | The Edge SWG must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). |
| ☐ | SV-279175r1170658_rule | The Edge SWG must display the standard mandatory DOD-approved notice and consent banner before granting access to the network. |
| ☐ | SV-279176r1170660_rule | The Edge SWG must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types. |
| ☐ | SV-279177r1170662_rule | The Edge SWG must ensure inbound and outbound traffic is monitored for compliance with remote access security policies. |
| ☐ | SV-279178r1170664_rule | The Edge SWG must be configured to comply with the required TLS settings in NIST SP 800-52. |
| ☐ | SV-279180r1170629_rule | The Edge SWG must be configured to remove or disable unrelated or unneeded application proxy services. |
| ☐ | SV-279187r1170651_rule | In the event of a system failure of the ALG function, the Edge SWG must save diagnostic information, log system messages, and load the most current security policies, rules, and signatures when restarted. |
| ☐ | SV-279194r1170667_rule | The Edge SWG must generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries. |
| ☐ | SV-279203r1170670_rule | The Edge SWG must control remote access methods. |
| ☐ | SV-279216r1170672_rule | The Edge SWG providing user authentication intermediary services must require users to reauthenticate when organization-defined circumstances or situations require reauthentication. |
| ☐ | SV-279217r1170674_rule | The Edge SWG using PKI-based user authentication must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network. |
| ☐ | SV-279219r1170647_rule | The Edge must implement load balancing to limit the effects of known and unknown types of denial-of-service (DoS) attacks. |
| ☐ | SV-279222r1170676_rule | The Edge SWG must fail securely in the event of an operational failure. |