Skip to content

Ivanti Sentry 9.x ALG Security Technical Implementation Guide

Rules, Groups, and Values defined within the XCCDF Benchmark

  • The Sentry must only allow incoming communications from organization-defined authorized sources routed to organization-defined authorized destinations.

    Unrestricted traffic may contain malicious traffic which poses a threat to an enclave or to other connected networks. Additionally, unrestricted traffic may transit a network, which uses bandwidth ...
    Rule Medium Severity
  • The Sentry must offload audit records onto a centralized log server in real time.

    Offloading ensures audit information does not get overwritten if the limited audit storage capacity is reached and also protects the audit record in case the system/component being audited is compr...
    Rule Low Severity
  • SRG-NET-000015-ALG-000016

    Group
  • The Sentry must enforce approved authorizations for logical access to information and system resources by enabling identity-based, role-based, and/or attribute-based security policies. These controls are enabled in MobileIron UEM (MobileIron Core) and applied by the Sentry for conditional access enforcement.

    Successful authentication through Sentry must not automatically give an entity access to resources behind Sentry. The lack of authorization-based access control could result in the immediate compro...
    Rule Medium Severity
  • SRG-NET-000018-ALG-000017

    Group
  • The Sentry must enforce approved authorizations for controlling the flow of information within the network based on attribute-based inspection of the source, destination, and headers, of the communications traffic.

    Information flow control regulates where information is allowed to travel within a network. The flow of all network traffic must be monitored and controlled so it does not introduce any unacceptabl...
    Rule Medium Severity
  • SRG-NET-000019-ALG-000018

    Group
  • SRG-NET-000074-ALG-000043

    Group
  • SRG-NET-000140-ALG-000094

    Group
  • SRG-NET-000062-ALG-000011

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules