Unified Endpoint Management Server Security Requirements Guide
Rules, Groups, and Values defined within the XCCDF Benchmark
-
SRG-APP-000001
Group -
SRG-APP-000002
Group -
The UEM server must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
A session time-out lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity of the information system, but does not log out because of the tempora...Rule Medium Severity -
SRG-APP-000003
Group -
The UEM server must initiate a session lock after a 15-minute period of inactivity.
A session time-out lock is a temporary action taken when a user stops work and moves away from the immediate physical vicinity of the information system, but does not log out because of the tempora...Rule Medium Severity -
SRG-APP-000004
Group -
SRG-APP-000005
Group -
SRG-APP-000014
Group -
The UEM server must use TLS 1.2, or higher, to protect the confidentiality of sensitive data during electronic dissemination using remote access.
Using older unauthorized versions or incorrectly configuring protocol negotiation makes the gateway vulnerable to known and unknown attacks that exploit vulnerabilities in this protocol. This requ...Rule Medium Severity -
SRG-APP-000023
Group -
SRG-APP-000024
Group -
The UEM server must automatically remove or disable temporary user accounts after 72 hours if supported by the UEM server.
If temporary user accounts remain active when no longer needed or for an excessive period, these accounts may be used to gain unauthorized access. To mitigate this risk, automated termination of al...Rule Medium Severity -
SRG-APP-000025
Group -
SRG-APP-000026
Group -
The UEM server must automatically audit account creation.
Once an attacker establishes access to a system, the attacker often attempts to create a persistent method of re-establishing access. One way to accomplish this is for the attacker to simply create...Rule Medium Severity -
SRG-APP-000027
Group -
SRG-APP-000028
Group -
SRG-APP-000029
Group -
The UEM server must automatically audit account removal actions.
When application accounts are removed, user accessibility is affected. Once an attacker establishes access to an application, the attacker often attempts to remove authorized accounts to disrupt se...Rule Medium Severity -
SRG-APP-000065
Group -
The UEM server must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.
By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute forcing, is reduced. Limits are imposed by locking the a...Rule Medium Severity -
SRG-APP-000068
Group -
SRG-APP-000069
Group -
The UEM server must retain the access banner until the user acknowledges acceptance of the access conditions.
The banner must be acknowledged by the user prior to allowing the user access to the application. This provides assurance that the user has seen the message and accepted the conditions for access. ...Rule Low Severity -
SRG-APP-000080
Group -
SRG-APP-000089
Group -
The UEM server must provide audit record generation capability for DoD-defined auditable events within all application components.
Without the capability to generate audit records, it would be difficult to establish, correlate, and investigate the events relating to an incident, or identify those responsible for one. Audit r...Rule Medium Severity -
SRG-APP-000089
Group -
SRG-APP-000090
Group -
The UEM server must be configured to allow only specific administrator roles to select which auditable events are to be audited.
Without the capability to restrict which roles and individuals can select which events are audited, unauthorized personnel may be able to prevent the auditing of critical events. Misconfigured audi...Rule Medium Severity -
SRG-APP-000091
Group -
The UEM server must generate audit records when successful/unsuccessful attempts to access privileges occur.
Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...Rule Medium Severity -
SRG-APP-000092
Group -
The UEM server must initiate session auditing upon startup.
If auditing is enabled late in the startup process, the actions of some start-up processes may not be audited. Some audit systems also maintain state information only available if auditing is enabl...Rule Medium Severity -
SRG-APP-000095
Group -
The UEM server must be configured to produce audit records containing information to establish what type of events occurred.
Without establishing what type of event occurred, it would be difficult to establish, correlate, and investigate the events relating to an incident, or identify those responsible for one. Audit r...Rule Medium Severity -
SRG-APP-000096
Group -
SRG-APP-000097
Group -
The UEM server must be configured to produce audit records containing information to establish where the events occurred.
Failure to generate these audit records makes it more difficult to identify or investigate attempted or successful compromises, potentially causing incidents to last longer than necessary. Satisf...Rule Medium Severity -
SRG-APP-000098
Group -
SRG-APP-000099
Group -
The UEM server must be configured to produce audit records that contain information to establish the outcome of the events.
Without information about the outcome of events, security personnel cannot make an accurate assessment as to whether an attack was successful or if changes were made to the security state of the sy...Rule Medium Severity -
SRG-APP-000100
Group -
The UEM server must be configured to generate audit records containing information that establishes the identity of any individual or process associated with the event.
Without information that establishes the identity of the subjects (i.e., users or processes acting on behalf of users) associated with the events, security personnel cannot determine responsibility...Rule Medium Severity -
SRG-APP-000101
Group -
SRG-APP-000108
Group -
The UEM SRG must alert the ISSO and SA (at a minimum) in the event of an audit processing failure.
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without this notification, the security personnel may be unaware of an ...Rule Medium Severity -
SRG-APP-000116
Group -
The UEM server must use host operating system clocks to generate time stamps for audit records.
Without an internal clock used as the reference for the time stored on each event to provide a trusted common reference for the time, forensic analysis would be impeded. Determining the correct tim...Rule Medium Severity -
SRG-APP-000118
Group
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.