| Checked | Name | Title |
|---|
| ☐ | SV-279248r1170510_rule | The Edge SWG must be configured to use FIPS mode. |
| ☐ | SV-279249r1170513_rule | The Edge SWG must be configured to use tlsv1.2 or greater. |
| ☐ | SV-279250r1170680_rule | The Edge SWG must be configured to assign appropriate user roles or access levels to authenticated users. |
| ☐ | SV-279251r1192886_rule | The Edge SWG must be configured to use at least two authentication servers for the purpose of authenticating users prior to granting administrative access. |
| ☐ | SV-279252r1170685_rule | The Edge SWG must be configured to send log data to at least one central log server for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO). |
| ☐ | SV-279253r1170687_rule | The Edge SWG must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes. |
| ☐ | SV-279254r1170689_rule | The Edge SWG must display the Standard Mandatory DOD Notice and Consent Banner before granting access to the device. |
| ☐ | SV-279255r1170692_rule | The Edge SWG must produce audit records containing information to establish when (date and time) the events occurred. |
| ☐ | SV-279256r1170694_rule | The Edge SWG must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable. |
| ☐ | SV-279257r1170535_rule | The Edge SWG must enforce a minimum 15-character password length. |
| ☐ | SV-279258r1170538_rule | The Edge SWG must enforce password complexity by requiring at least one uppercase character be used. |
| ☐ | SV-279259r1170541_rule | The Edge SWG must enforce a 60-day password lifetime. |
| ☐ | SV-279260r1170544_rule | The Edge SWG must enforce password complexity by requiring at least one lowercase character be used. |
| ☐ | SV-279261r1170547_rule | The Edge SWG must enforce password complexity by requiring at least one numeric character be used. |
| ☐ | SV-279262r1170550_rule | The Edge SWG must enforce password complexity by requiring at least one special character be used. |
| ☐ | SV-279263r1170553_rule | The Edge SWG must require that when a password is changed, the characters are changed in at least eight of the positions within the password. |
| ☐ | SV-279264r1172802_rule | The Edge SWG must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity except to fulfill documented and validated mission requirements. |
| ☐ | SV-279265r1170559_rule | The Edge SWG must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements. |
| ☐ | SV-279266r1170696_rule | The Edge SWG must generate an immediate real-time alert of all audit failure events requiring real-time alerts. |
| ☐ | SV-279268r1170603_rule | The Edge SWG must be configured to authenticate SNMP messages using a FIPS-validated Keyed-Hash Message Authentication Code (HMAC). |
| ☐ | SV-279269r1170698_rule | The Edge SWG must authenticate Network Time Protocol sources using authentication that is cryptographically based. |
| ☐ | SV-279270r1170571_rule | The Edge SWG must prohibit the use of cached authenticators after an organization-defined time period. |
| ☐ | SV-279271r1170700_rule | The Edge SWG must be configured to protect against known types of denial-of-service (DoS) attacks by employing organization-defined security safeguards. |
| ☐ | SV-279272r1172804_rule | The Edge SWG must be configured to conduct backups of system-level information contained in the information system when changes occur. |
| ☐ | SV-279273r1170704_rule | The Edge SWG must obtain its public key certificates from an appropriate certificate policy through an approved service provider. |
| ☐ | SV-279274r1172805_rule | The Edge SWG must limit the number of concurrent management sessions to a maximum of three. |
| ☐ | SV-279275r1170586_rule | The Edge SWG must be running an operating system release that is currently supported by the vendor. |
| ☐ | SV-279276r1170589_rule | The Edge SWG must be configured to allow user selection of long passwords and passphrases, including spaces and all printable characters for password-based authentication. |
| ☐ | SV-279277r1170713_rule | The Edge SWG must be configured to implement a local cache of revocation data to support path discovery and validation for public key-based authentication. |
| ☐ | SV-279283r1170595_rule | The Edge SWG must be configured to verify when users create or update passwords, and that the passwords are not found on the list of commonly used, expected, or compromised passwords in IA-5 (1) (a) for password-based authentication. |