Skip to content

I - Mission Critical Classified

Rules and Groups employed by this XCCDF Profile

  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • Separate MySQL user accounts with limited privileges must be created within Jamf Pro EMM.

    &lt;VulnDiscussion&gt;If separate MySQL accounts with limited privileges are not created an adversary could gain unauthorized access to the applica...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • MySQL database backups must be scheduled in Jamf Pro EMM.

    &lt;VulnDiscussion&gt;Database backups are a recognized best practice to protect against key data loss and possible adverse impacts to the mission ...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • The MySQL DatabasePassword key must be removed or set to a blank value in the database configuration file in Jamf Pro EMM.

    &lt;VulnDiscussion&gt;If the database password is not removed or set to a blank value in the configuration file, the user is not forced to enter th...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • The Jamf Pro EMM local accounts password must be configured with length of 15 characters.

    &lt;VulnDiscussion&gt;The shorter the password, the lower the number of possible combinations that need to be tested before the password is comprom...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • The Jamf Pro EMM local accounts must be configured with at least one lowercase character.

    &lt;VulnDiscussion&gt;Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • The Jamf Pro EMM local accounts must be configured with at least one uppercase character.

    &lt;VulnDiscussion&gt;Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • The Jamf Pro EMM local accounts must be configured with at least one number.

    &lt;VulnDiscussion&gt;Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • The Jamf Pro EMM local accounts must be configured with at least one special character.

    &lt;VulnDiscussion&gt;Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, ...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • The Jamf Pro EMM local accounts must be configured with password minimum lifetime of 24 hours.

    &lt;VulnDiscussion&gt;Enforcing a minimum password lifetime helps prevent repeated password changes to defeat the password reuse or history enforce...
    Rule Medium Severity
  • PP-MDM-991000

    <GroupDescription></GroupDescription>
    Group
  • The Jamf Pro EMM local accounts must be configured with password maximum lifetime of 3 months.

    &lt;VulnDiscussion&gt;Any password, no matter how complex, can eventually be cracked. Therefore, passwords need to be changed at specific intervals...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules