Skip to content

IBM DataPower Network Device Management Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000125-NDM-000241

    Group
  • The DataPower Gateway must back up audit records at least every seven days onto a different system or system component than the system or component being audited.

    Protection of log data includes assuring log data is not accidentally lost or deleted. Regularly backing up audit records to a different system or onto separate media than the system being audited ...
    Rule Low Severity
  • SRG-APP-000131-NDM-000243

    Group
  • SRG-APP-000142-NDM-000245

    Group
  • SRG-APP-000164-NDM-000252

    Group
  • The DataPower Gateway must enforce a minimum 15-character password length.

    Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to d...
    Rule Medium Severity
  • SRG-APP-000165-NDM-000253

    Group
  • The DataPower Gateway must prohibit password reuse for a minimum of five generations.

    Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. To meet password policy requirements, passwords need t...
    Rule Medium Severity
  • SRG-APP-000166-NDM-000254

    Group
  • If multifactor authentication is not supported and passwords must be used, the DataPower Gateway must enforce password complexity by requiring that at least one upper-case character be used.

    Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisti...
    Rule Medium Severity
  • SRG-APP-000167-NDM-000255

    Group
  • SRG-APP-000168-NDM-000256

    Group
  • If multifactor authentication is not supported and passwords must be used, the DataPower Gateway must enforce password complexity by requiring that at least one numeric character be used.

    Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resistin...
    Rule Medium Severity
  • SRG-APP-000169-NDM-000257

    Group
  • SRG-APP-000177-NDM-000263

    Group
  • The DataPower Gateway must map the authenticated identity to the user account for PKI-based authentication.

    Authorization for access to any network device requires an approved and assigned individual account identifier. To ensure only the assigned individual is using the account, the account must be boun...
    Rule Medium Severity
  • SRG-APP-000179-NDM-000265

    Group
  • The DataPower Gateway must use mechanisms meeting the requirements of applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance for authentication to a cryptographic module.

    Unapproved mechanisms that are used for authentication to the cryptographic module are not verified and therefore cannot be relied upon to provide confidentiality or integrity, and DoD data may be ...
    Rule Medium Severity
  • SRG-APP-000190-NDM-000267

    Group
  • SRG-APP-000224-NDM-000270

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules