STIGUI
V-284544CAT II — Medium severitySV-284544r1244957_rule

The Ivanti Policy Secure must be configured to protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by logically separated communications paths.

Rule version IVPS-NM-000073 · STIG v1 · 2026-07-09

Discussion

Nonlocal maintenance and diagnostic activities are conducted by individuals who communicate through either an external or internal network. Communications paths can be logically separated using encryption.

Check

1. In the Web UI, navigate to Administrators >> Admins Realms >> Admin Users >> Authentication Policy. 2. Click the configured admin realm being used for common access card (CAC)/public key infrastructure (PKI) token admin logins. 3. Click the "Authentication Policy" tab, then click "Source IP".

In "Administrator Sign in Port" if there are any ports selected for "Administrator Sign in" other than "Management Port", this is a finding.

Fix

1. In the Web UI, navigate to Administrators >> Admins Realms >> Admin Users >> Authentication Policy. 2. Click the configured admin realm used for CAC/PKI token admin logins. 3. Click the "Authentication Policy" tab, then click "Source IP". 4. In "Administrator Sign in Port" under Administrator Sign in Ports Select only the "Management Port".

Identifiers

Group ID
V-284544
Group title
SRG-APP-000880-NDM-000290
Rule ID
SV-284544r1244957_rule
Check ID
C-89109r1244263_chk
Fix ID
F-89014r1244665_fix