Skip to content

IBM MQ Appliance v9.0 NDM Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • SRG-APP-000373-NDM-000298

    Group
  • The MQ Appliance network device must be configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.

    The loss of connectivity to a particular authoritative time source will result in the loss of time synchronization (free-run mode) and increasingly inaccurate time stamps on audit events and other ...
    Rule Medium Severity
  • SRG-APP-000391-NDM-000308

    Group
  • SRG-APP-000411-NDM-000330

    Group
  • Applications used for nonlocal maintenance sessions using the MQ Appliance WebGUI must implement cryptographic mechanisms to protect the confidentiality and integrity of nonlocal maintenance and diagnostic communications.

    This requires the use of secure protocols instead of their unsecured counterparts, such as SSH instead of telnet, SCP instead of FTP, and HTTPS instead of HTTP. If unsecured protocols (lacking cryp...
    Rule Medium Severity
  • SRG-APP-000506-NDM-000323

    Group
  • SRG-APP-000509-NDM-000324

    Group
  • The MQ Appliance network device must generate audit records for all account creations, modifications, disabling, and termination events.

    Without generating audit records that are specific to the security and mission needs of the organization, it would be difficult to establish, correlate, and investigate the events relating to an in...
    Rule Medium Severity
  • SRG-APP-000515-NDM-000325

    Group
  • The MQ Appliance network device must off-load audit records onto a different system or media than the system being audited.

    Information stored in one location is vulnerable to accidental or incidental deletion or alteration. Using a syslog logging target, the MQ Appliance logs all audit records to the syslog. Logging ma...
    Rule Medium Severity
  • SRG-APP-000516-NDM-000333

    Group
  • SRG-APP-000516-NDM-000336

    Group
  • Administrative accounts for device management must be configured on the authentication server and not the MQ Appliance network device itself (except for the emergency administration account).

    The use of authentication servers or other centralized management servers for providing centralized authentication services is required for network MQ Appliance device management. Maintaining local...
    Rule Medium Severity
  • SRG-APP-000516-NDM-000337

    Group
  • Access to the MQ Appliance network device must employ automated mechanisms to centrally apply authentication settings.

    The use of authentication servers or other centralized management servers for providing centralized authentication services is required for network MQ Appliance device management. Maintaining local...
    Rule Medium Severity
  • SRG-APP-000516-NDM-000340

    Group
  • SRG-APP-000516-NDM-000344

    Group
  • SRG-APP-000408-NDM-000314

    Group
  • SRG-APP-000001-NDM-000200

    Group
  • Access to the MQ Appliance network device must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.

    MQ Appliance device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions ...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules