CCI-000054
Limit the number of concurrent sessions for each organization-defined account and/or account type to an organization-defined number.
Compliance Guardian must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

The CA API Gateway providing user access control intermediary services must limit users to two concurrent sessions.
1 rule found Severity: Medium

Delivery Controller must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Docker Enterprise Per User Limit Login Session Control in the Universal Control Plane (UCP) Admin Settings must be set to an organization-defined value for all accounts and/or account types.
1 rule found Severity: Low

1 rule found Severity: Medium

CounterACT must limit the number of concurrent sessions to an organization-defined number for each administrator account type.
1 rule found Severity: Low

Infoblox systems that perform zone transfers to non-Grid DNS servers must limit the number of concurrent sessions for zone transfers.
1 rule found Severity: Medium

The Infoblox system must limit the number of concurrent client connections to the number of allowed dynamic update clients.
2 rules found Severity: Medium

The IBM Aspera High-Speed Transfer Endpoint must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

The IBM Aspera High-Speed Transfer Server must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

The MQ Appliance messaging server must protect against or limit the effects of all types of Denial of Service (DoS) attacks by employing operationally-defined security safeguards.
1 rule found Severity: Medium

The WebSphere Application Server maximum in-memory session count must be set according to application requirements.
1 rule found Severity: Medium

The Ivanti MobileIron Core server must limit the number of concurrent sessions per privileged user account to three or less concurrent sessions.
1 rule found Severity: Medium

MobileIron Sentry must limit the number of concurrent sessions for the CLISH interface to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

MobileIron Sentry must be configured to limit the network access of the Sentry System Manager Portal behind the corporate firewall and whitelist source IP range.
1 rule found Severity: Medium

The ISEC7 EMM Suite must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Nutanix AOS must limit the number of concurrent sessions to ten for all accounts and/or account types.
1 rule found Severity: Medium

OHS must have the mpm property set to use the worker Multi-Processing Module (MPM) as the preferred means to limit the number of allowed simultaneous requests.
1 rule found Severity: Medium

OHS must have the mpm_prefork_module directive disabled so as not conflict with the worker directive used to limit the number of allowed simultaneous requests.
1 rule found Severity: Medium

OHS must have the MaxClients directive defined to limit the number of allowed simultaneous requests.
1 rule found Severity: Medium

OHS must limit the number of threads within a worker process to limit the number of allowed simultaneous requests.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

OHS must have the LoadModule ossl_module directive enabled to implement required cryptographic protections using cryptographic modules complying with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance when encrypting data that must be compartmentalized.
1 rule found Severity: High

Riverbed Optimization System (RiOS) must limit the number of concurrent sessions to one (1) for each administrator account and/or administrator account type.
1 rule found Severity: Medium

The Samsung SDS EMM must limit the number of concurrent sessions to one session for all accounts and/or account types.
1 rule found Severity: Medium

The Tanium max_soap_sessions_total setting must be explicitly enabled to limit the number of simultaneous sessions.
4 rules found Severity: Medium

The Tanium max_soap_sessions_per_user setting must be explicitly enabled to limit the number of simultaneous sessions.
4 rules found Severity: Medium

The Tanium soap_max_keep_alive setting must be explicitly enabled to limit the number of simultaneous sessions.
2 rules found Severity: Medium

The Tanium Operating System (TanOS) must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
2 rules found Severity: Medium

The Ubuntu operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.
2 rules found Severity: Low

2 rules found Severity: Medium

The DBMS must limit the number of concurrent sessions for each system account to an organization-defined number of sessions.
2 rules found Severity: Medium

The DBMS must protect against or limit the effects of the organization-defined types of Denial of Service (DoS) attacks.
1 rule found Severity: Medium

PostgreSQL must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
3 rules found Severity: Medium

The Red Hat Enterprise Linux operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.
1 rule found Severity: Low

The EDB Postgres Advanced Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
2 rules found Severity: Medium

The F5 BIG-IP appliance must be configured to set the "Max In Progress Sessions per Client IP" value to 10 or less.
1 rule found Severity: Low

The BIG-IP appliance must limit the number of concurrent sessions to the Configuration Utility to 10 or an organization-defined number.
1 rule found Severity: Medium

The BIG-IP Core implementation must be configured to limit the number of concurrent sessions to an organization-defined number for virtual servers.
1 rule found Severity: High

1 rule found Severity: Low

The BIND 9.x secondary name server must limit the number of zones requested from a single master name server.
1 rule found Severity: Medium

The BIND 9.x secondary name server must limit the total number of zones the name server can request at any one time.
1 rule found Severity: Medium

The BIND 9.x server implementation must limit the number of concurrent session client connections to the number of allowed dynamic update clients.
1 rule found Severity: Medium

A BIND 9.x master name server must limit the number of concurrent zone transfers between authorized secondary name servers.
1 rule found Severity: Medium

For interactive sessions, IDMS must limit the number of concurrent sessions for the same user to one or allow unlimited sessions.
1 rule found Severity: Medium

The DBMS must develop a procedure to limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
1 rule found Severity: Medium

The Cisco switch must be configured to limit the number of concurrent management sessions to an organization-defined number.
3 rules found Severity: Medium

The DNS implementation must limit the number of concurrent sessions for zone transfers to the number of secondary name servers.
1 rule found Severity: Medium

The DNS implementation must limit the number of concurrent sessions client connections to the number of allowed dynamic update clients.
1 rule found Severity: Medium

The Enterprise Voice, Video, and Messaging Endpoint must be configured to limit the number of concurrent sessions to an organizationally defined number.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to set the "Max In Progress Sessions per Client IP" value to 10 or an organizational-defined number.
1 rule found Severity: Low

The Enterprise Voice, Video, and Messaging Session Manager must limit the number of concurrent management sessions to an organizationally defined limit.
1 rule found Severity: Medium

The F5 BIG-IP appliance must be configured to limit the number of concurrent sessions to the Configuration Utility to 10 or an organization-defined number.
1 rule found Severity: Medium

1 rule found Severity: Medium

The HPE Nimble must limit the number of concurrent sessions to an organization-defined number for each administrator account.
1 rule found Severity: Medium

1 rule found Severity: Medium

The ISEC7 SPHERE must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

Sentry must limit the number of concurrent sessions for the CLISH interface to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

Sentry must be configured to limit the network access of the Sentry System Manager Portal behind the corporate firewall and whitelist source IP range.
1 rule found Severity: Medium

The ICS must be configured to limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Ivanti EPMM server must limit the number of concurrent sessions per privileged user account to three or less concurrent sessions.
1 rule found Severity: Medium

The Juniper EX switch must be configured to limit the number of concurrent management sessions to 10 or an organization-defined value.
1 rule found Severity: Medium

MarkLogic Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
1 rule found Severity: Low

The IIS 10.0 websites MaxConnections setting must be configured to limit the number of allowed simultaneous session requests.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Windows DNS primary server must only send zone transfers to a specific list of secondary name servers.
1 rule found Severity: Medium

The network device must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

The Oracle Linux operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.
1 rule found Severity: Low

MySQL Database Server 8.0 must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
1 rule found Severity: Medium

Automation Controller must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

1 rule found Severity: Low

The TippingPoint SMS must limit the maximum number of concurrent active sessions to one for the account of last resort.
1 rule found Severity: Low

The TippingPoint SMS must limit total number of user sessions for privileged uses to a maximum of 10.
1 rule found Severity: Low

The Tanium "max_soap_sessions_total" setting must be explicitly enabled to limit the number of simultaneous sessions.
1 rule found Severity: Medium

The Tanium "max_soap_sessions_per_user" setting must be explicitly enabled to limit the number of simultaneous sessions.
1 rule found Severity: Medium

1 rule found Severity: Low

1 rule found Severity: Medium

NixOS must be configured to limit the number of concurrent sessions to ten for all accounts and/or account types.
1 rule found Severity: Low

3 rules found Severity: Medium

The ALG providing user access control intermediary services must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

The application server must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

1 rule found Severity: Medium

Ubuntu 22.04 LTS must limit the number of concurrent sessions to ten for all accounts and/or account types.
1 rule found Severity: Low

The Cisco router must be configured to limit the number of concurrent management sessions to an organization-defined number.
3 rules found Severity: Medium

AlmaLinux OS 9 must limit the number of concurrent sessions to ten for all accounts and/or account types.
1 rule found Severity: Low

The DBMS must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
1 rule found Severity: Medium

The Dell OS10 Switch must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

1 rule found Severity: Low

The operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.
1 rule found Severity: Low

AOS must limit the number of concurrent sessions to a maximum of three for each administrator account and/or administrator account type.
1 rule found Severity: Medium

The HYCU virtual appliance must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

AOS, when used as a VPN Gateway, must limit the number of concurrent sessions for user accounts to one or to an organization-defined number.
1 rule found Severity: Medium

The Juniper router must be configured to limit the number of concurrent management sessions to an organization-defined number.
1 rule found Severity: Medium

The Juniper SRX Services Gateway must limit the number of concurrent sessions to a maximum of 10 or less for remote access using SSH.
1 rule found Severity: Low

The Mainframe Product must limit the number of concurrent sessions to three for all accounts and/or account types.
1 rule found Severity: Medium

MariaDB must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
1 rule found Severity: Low

The Juniper SRX Services Gateway VPN must limit the number of concurrent sessions for user accounts to one (1) and administrative accounts to three (3), or set to an organization-defined number.
1 rule found Severity: Medium

SQL Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
1 rule found Severity: Medium

1 rule found Severity: Low

1 rule found Severity: Low

1 rule found Severity: Low

The SUSE operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.
2 rules found Severity: Low

The operating system must limit the number of concurrent sessions for each account to an organization-defined number of sessions.
2 rules found Severity: Low

1 rule found Severity: Medium

The UEM server must limit the number of concurrent sessions per privileged user account to three or less concurrent sessions.
1 rule found Severity: Medium

The NSX Manager must be configured to protect against denial-of-service (DoS) attacks by limit the number of concurrent sessions to an organization-defined number.
1 rule found Severity: Medium

ESX Agent Manager must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

Lookup Service must limit the amount of time that each Transport Control Protocol (TCP) connection is kept alive.
1 rule found Severity: Medium

1 rule found Severity: Medium

Performance Charts must limit the amount of time that each Transport Control Protocol (TCP) connection is kept alive.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Photon operating system must limit the number of concurrent sessions to 10 for all accounts and/or account types.
1 rule found Severity: Medium

The vCenter ESX Agent Manager service must limit the number of maximum concurrent connections permitted.
2 rules found Severity: Medium

The vCenter ESX Agent Manager service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

The vCenter ESX Agent Manager service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

vSphere UI must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
1 rule found Severity: Medium

The Security Token Service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

2 rules found Severity: Medium

The vCenter Lookup service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

The vCenter Lookup service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

2 rules found Severity: Medium

The vCenter Perfcharts service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

The vCenter Perfcharts service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

The Photon operating system must limit the number of concurrent sessions to ten for all accounts and/or account types.
2 rules found Severity: Low

The VPN Gateway must limit the number of concurrent sessions for user accounts to 1 or to an organization-defined number.
1 rule found Severity: Medium

2 rules found Severity: Medium

2 rules found Severity: Medium

The vCenter STS service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

The vCenter STS service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

2 rules found Severity: Medium

The vCenter UI service must limit the amount of time that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

The vCenter UI service must limit the number of times that each Transmission Control Protocol (TCP) connection is kept alive.
2 rules found Severity: Medium

2 rules found Severity: Medium

The A10 Networks ADC must limit the number of concurrent sessions to one (1) for each administrator account and/or administrator account type.
1 rule found Severity: Medium

DocAve must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
1 rule found Severity: Medium

The HP FlexFabric Switch must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Low

The HYCU 4.1 application and server must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

DB2 must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
1 rule found Severity: Medium

Access to the MQ Appliance network device must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

Infoblox systems which perform zone transfers to non-Infoblox Grid DNS servers must be configured to limit the number of concurrent sessions for zone transfers.
1 rule found Severity: Low

1 rule found Severity: Low

The F5 BIG-IP appliance providing user access control intermediary services must limit the number of concurrent sessions to one or an organization-defined number for each access profile.
1 rule found Severity: Medium

1 rule found Severity: Medium

1 rule found Severity: Medium

The Arista network device must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.
1 rule found Severity: Medium

The Cisco ASA must be configured to limit the number of concurrent management sessions to an organization-defined number.
1 rule found Severity: Medium

1 rule found Severity: Medium

The Riverbed NetProfiler must be configured to limit the number of concurrent sessions to one for the locally defined administrator account.
1 rule found Severity: Low
