UCF STIG Viewer Logo

The UEM server must prohibit the use of cached authenticators after an organization-defined time period.


Overview

Finding ID Version Rule ID IA Controls Severity
V-234543 SRG-APP-000400-UEM-000271 SV-234543r617355_rule Medium
Description
If cached authentication information is out-of-date, the validity of the authentication information may be questionable. According to the CNSS 1253, the IA-5(13) control which is tied to this requirement is not defined at the DoD-level. The organization should specify this value based on numerous factors, including the application in question, the data it hosts and the associated exposures/risks.
STIG Date
Unified Endpoint Management Server Security Requirements Guide 2020-12-14

Details

Check Text ( C-37728r615986_chk )
Requirement is Not Applicable when the UEM server is configured to use DoD Central Directory Service for administrator account authentication.

Verify the UEM server prohibits the use of cached authenticators after an organization-defined time period.

If the UEM server does not prohibit the use of cached authenticators after an organization-defined time period, this is a finding.
Fix Text (F-37693r615273_fix)
Configure the UEM server to prohibit the use of cached authenticators after an organization-defined time period.