III - Administrative Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-NET-000512-ALG-000062
<GroupDescription></GroupDescription>Group -
The IBM Aspera Faspex private/secret cryptographic keys file must have a mode of 0600 or less permissive to prevent unauthorized read access.
<VulnDiscussion>Private key data is used to prove that the entity presenting a public key certificate is the certificate's rightful owner. Co...Rule Medium Severity -
SRG-NET-000512-ALG-000062
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex must allow the use of a temporary password for logins with an immediate change to a permanent password.
<VulnDiscussion>Without providing this capability, an account may be created without a password. Non-repudiation cannot be guaranteed once an...Rule Medium Severity -
SRG-NET-000041-ALG-000022
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex must be configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to the system.
<VulnDiscussion>Display of a standardized and approved use notification before granting access to the network ensures privacy and security no...Rule Low Severity -
SRG-NET-000512-ALG-000062
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex must disable account identifiers after 35 days of inactivity.
<VulnDiscussion>Inactive identifiers pose a risk to systems and applications because attackers may exploit an inactive identifier and potenti...Rule Medium Severity -
SRG-NET-000339-ALG-000090
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex must implement multifactor authentication for remote access to non-privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
<VulnDiscussion>For remote access to non-privileged accounts, the purpose of requiring a device that is separate from the information system ...Rule Medium Severity -
SRG-NET-000512-ALG-000062
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex must lock accounts after three unsuccessful login attempts within a 15-minute timeframe.
<VulnDiscussion>By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise...Rule Medium Severity -
SRG-NET-000053-ALG-000001
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex must prevent concurrent logins for all accounts.
<VulnDiscussion>Limiting the number of current sessions per user is helpful in limiting risks related to DoS attacks. This requirement addre...Rule Medium Severity -
SRG-NET-000512-ALG-000062
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex must require password complexity features to be enabled.
<VulnDiscussion>Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...Rule Medium Severity -
SRG-NET-000169-ALG-000102
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
<VulnDiscussion>Lack of authentication enables anyone to gain access to the network or possibly a network element that provides opportunity f...Rule Medium Severity -
SRG-NET-000512-ALG-000062
<GroupDescription></GroupDescription>Group -
IBM Aspera Faspex passwords must be prohibited from reuse for a minimum of five generations.
<VulnDiscussion>Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.