Skip to content

Fortinet FortiGate Firewall NDM Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000120-NDM-000237

    <GroupDescription></GroupDescription>
    Group
  • The FortiGate device must protect audit information from unauthorized deletion.

    &lt;VulnDiscussion&gt;Audit information includes all information (e.g., audit records, audit settings, and audit reports) needed to successfully au...
    Rule Medium Severity
  • SRG-APP-000121-NDM-000238

    <GroupDescription></GroupDescription>
    Group
  • The FortiGate device must protect audit tools from unauthorized access.

    &lt;VulnDiscussion&gt;Protecting audit data also includes identifying and protecting the tools used to view and manipulate log data. Therefore, pro...
    Rule Medium Severity
  • SRG-APP-000122-NDM-000239

    <GroupDescription></GroupDescription>
    Group
  • The FortiGate device must use LDAP for authentication.

    &lt;VulnDiscussion&gt;Centralized management of authentication settings increases the security of remote and nonlocal access methods. This control ...
    Rule Medium Severity
  • The FortiGate device must protect audit tools from unauthorized modification.

    &lt;VulnDiscussion&gt;Protecting audit data also includes identifying and protecting the tools used to view and manipulate log data. Therefore, pro...
    Rule Medium Severity
  • SRG-APP-000378-NDM-000302

    <GroupDescription></GroupDescription>
    Group
  • The FortiGate device must prohibit installation of software without explicit privileged status.

    &lt;VulnDiscussion&gt;Allowing anyone to install software, without explicit privileges, creates the risk that untested or potentially malicious sof...
    Rule Medium Severity
  • SRG-APP-000380-NDM-000304

    <GroupDescription></GroupDescription>
    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules