Applications Systems

SCM policy engine – excluded rules

The SCM policy engine is an unofficial implementation of STIG policy rules. Not all rules are included. This article provides a list of rules that are not included.

First published date

8/24/2020 7:29 PM

Last published date

8/25/2020 7:21 PM

Overview

Not all STIG policy rules are included in the SCM policy engine. This article provides a list of rules that are not included.

Product section

Server Configuration Monitor

Resolution

Out-of-the-box policies in SCM help you to determine compliance with a subset of the official standard Security Technical Implementation Guides (STIG) policies (based on Microsoft Windows Server 2016 STIG - Ver 1, Rel 10" XCCDF). The out-of-the-box STIG policies included with SCM are as follows:
  • Windows Server 2016 (version 1, rel. 10)
  • IIS 8.5 STIG (version 1, rel. 9)
  • SQL Server 2016 (version 1, rel. 10)
Rules not included in the out-of-the-box Windows Server 2016 STIG policy are as follows:
  • V-73217 - Users with Administrative privileges must have separate accounts for administrative duties and normal operational tasks.
  • V-73219 - Only administrators responsible for the domain controller must have Administrator rights on the system.
  • V-73221 - Only administrators responsible for the member server or standalone system must have Administrator rights on the system.
  • V-73225 - Administrative accounts must not be used with applications that access the Internet, such as web browsers, or with potential Internet sources, such as email.
  • V-73227 - Members of the Backup Operators group must have separate accounts for backup duties and normal operational tasks.
  • V-73229 - Manually managed application account passwords must be at least 15 characters in length.
  • V-73231 - Manually managed application account passwords must be changed at least annually or when a system administrator with knowledge of the password leaves the organization.
  • V-73233 - Shared user accounts must not be permitted on the system.
  • V-73235 - Windows Server 2016 must employ a deny-all, permit-by-exception policy to allow the execution of authorized software programs.
  • V-73241 - The Windows Server 2016 system must use an anti-virus program.
  • V-73245 - Servers must have a host-based intrusion detection or prevention system.
  • V-73265 - System files must be monitored for unauthorized changes.
  • V-73267 - Non-system-created file shares on a system must limit access to groups that require it.
  • V-73271 - Software certificate installation files must be removed from Windows Server 2016.
  • V-73273 - Systems requiring data at rest protections must employ cryptographic mechanisms to prevent unauthorized disclosure and modification of the information at rest.
  • V-73275 - Protection methods such as TLS, encrypted VPNs, or IPsec must be implemented if the data owner has a strict requirement for ensuring data integrity and confidentiality is maintained at every step of the data transfer and handling process.
  • V-73277 - The roles and features required by the system must be documented.
  • V-73279 - A host-based firewall must be installed and enabled on the system.
  • V-73281 - Windows Server 2016 must employ automated mechanisms to determine the state of system components with regard to flaw remediation using the following frequency: continuously, where Host Based Security System (HBSS) is used; 30 days, for any additional internal network scans not covered by HBSS; and annually, for external scans by Computer Network Defense Service Provider (CNDSP).
  • V-73283 - Windows Server 2016 must automatically remove or disable temporary user accounts after 72 hours.
  • V-73285 - Windows Server 2016 must automatically remove or disable emergency accounts after the crisis is resolved or within 72 hours.
  • V-73289 - The Microsoft FTP service must not be installed unless required.
  • V-73303 - FTP servers must be configured to prevent anonymous logons.
  • V-73305 - FTP servers must be configured to prevent access to the system drive.
  • V-73373 - Active Directory Group Policy objects must have proper access control permissions.
  • V-73381 - Domain controllers must run on a machine dedicated to that function.
  • V-73383 - Separate, NSA-approved (Type 1) cryptography must be used to protect the directory data in transit for directory service implementations at a classified confidentiality level when replication data traverses a network cleared to a lower level than the data.
  • V-73385 - Directory data (outside the root DSE) of a non-public directory must be configured to prevent anonymous access.
  • V-73389 - Active Directory Group Policy objects must be configured with proper audit settings.
  • V-73401 - Audit records must be backed up to a different system or media than the system being audited.
  • V-73403 - Windows Server 2016 must, at a minimum, off-load audit records of interconnected systems in real time and off-load standalone systems weekly.
  • V-73553 - The Application event log size must be configured to 32768 KB or greater.
  • V-73555 - The Security event log size must be configured to 196608 KB or greater.
  • V-73557 - The System event log size must be configured to 32768 KB or greater.
  • V-73613 - Domain Controller PKI certificates must be issued by the DoD PKI or an approved External Certificate Authority (ECA).
  • V-73615 - PKI certificates associated with user accounts must be issued by the DoD PKI or an approved External Certificate Authority (ECA).
Rules not included in the out-of-the-box SQL Server 2016 STIG policy are as follows:
  • V-76679 - The IIS 8.5 web server remote authors or content providers must only use secure encrypted logons and connections to upload web server content.
  • V-76685 - An IIS 8.5 web server behind a load balancer or proxy server, must produce log records containing the source client IP and destination information.
  • V-76695 - The log information from the IIS 8.5 web server must be protected from unauthorized modification or deletion.
  • V-76697 - The log data and records from the IIS 8.5 web server must be backed up onto a different system or media.
  • V-76699 - The IIS 8.5 web server must not perform user management for hosted applications.
  • V-76701 - The IIS 8.5 web server must only contain functions necessary for operation.
  • V-76705 - All IIS 8.5 web server sample code, example applications, and tutorials must be removed from a production IIS 8.5 server.
  • V-76707 - The accounts created by uninstalled features (i.e., tools, utilities, specific, etc.) must be deleted from the IIS 8.5 server.
  • V-76709 - The IIS 8.5 web server must be reviewed on a regular basis to remove any Operating System features, utility programs, plug-ins, and modules not necessary for operation.
  • V-76715 - The IIS 8.5 web server must perform RFC 5280-compliant certification path validation.
  • V-76717 - Java software installed on a production IIS 8.5 web server must be limited to .class files and the Java Virtual Machine.
  • V-76719 - IIS 8.5 Web server accounts accessing the directory tree, the shell, or other operating system functions and utilities must only be administrative accounts.
  • V-76721 - The IIS 8.5 web server must separate the hosted applications from hosted web server management functionality.
  • V-76729 - The IIS 8.5 web server must augment re-creation to a stable and known baseline.
  • V-76735 - The IIS 8.5 web server Indexing must only index web content.
  • V-76739 - Remote access to the IIS 8.5 web server must follow access policy or work in conjunction with enterprise tools designed to enforce policy requirements.
  • V-76741 - The IIS 8.5 web server must restrict inbound connections from nonsecure zones.
  • V-76743 - The IIS 8.5 web server must provide the capability to immediately disconnect or disable remote access to the hosted applications.
  • V-76747 - The IIS 8.5 web server must use a logging mechanism that is configured to allocate log record storage capacity large enough to accommodate the logging requirements of the IIS 8.5 web server.
  • V-76749 - Access to web administration tools must be restricted to the web manager and the web managers designees.
  • V-76751 - The IIS 8.5 web server must not be running on a system providing any other role.
  • V-76755 - The IIS 8.5 web server must be tuned to handle the operational requirements of the hosted application.
  • V-76761 - A web server must maintain the confidentiality of controlled information during transmission through the use of an approved TLS version.
  • V-76765 - All accounts installed with the IIS 8.5 web server software and tools must have passwords assigned and default passwords changed.
  • V-76767 - The File System Object component must be disabled on the IIS 8.5 web server.
  • V-95633 - The IIS 8.5 MaxConnections setting must be configured to limit the number of allowed simultaneous session requests.
Rules not included in the out-of-the-box SQL Server 2016 STIG policy are as follows:
  • V-79119 - SQL Server must limit the number of concurrent sessions to an organization-defined number per user for all accounts and/or account types.
  • V-79123 - SQL Server must be configured to utilize the most-secure authentication method available.
  • V-79127 - SQL Server must protect against a user falsely repudiating by ensuring all accounts are individual, unique, and not shared.
  • V-79133 - SQL Server must be configured to generate audit records for DoD-defined auditable events within all DBMS/database components.
  • V-79135 - SQL Server must allow only the ISSM (or individuals or roles appointed by the ISSM) to select which auditable events are to be audited.
  • V-79145 - SQL Server must include additional, more detailed, organization-defined information in the audit records for audit events identified by type, location, or subject.
  • V-79151 - The audit information produced by SQL Server must be protected from unauthorized read access.
  • V-79153 - The audit information produced by SQL Server must be protected from unauthorized modification.
  • V-79155 - The audit information produced by SQL Server must be protected from unauthorized deletion.
  • V-79163 - SQL Server must limit privileges to change software modules and links to software external to SQL Server.
  • V-79165 - SQL Server must limit privileges to change software modules, to include stored procedures, functions and triggers, and links to software external to SQL Server.
  • V-79167 - SQL Server software installation account must be restricted to authorized users.
  • V-79169 - Database software, including DBMS configuration files, must be stored in dedicated directories, separate from the host OS and other applications.
  • V-79173 - Unused database components, DBMS software, and database objects must be removed.
  • V-79175 - Unused database components that are integrated in SQL Server and cannot be uninstalled must be disabled.
  • V-79187 - SQL Server must be configured to prohibit or restrict the use of organization-defined ports, as defined in the PPSM CAL and vulnerability assessments.
  • V-79189 - SQL Server must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
  • V-79201 - SQL Server must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
  • V-79205 - SQL Server must protect the confidentiality and integrity of all information at rest.
  • V-79207 - The Service Master Key must be backed up, stored offline and off-site.
  • V-79209 - The Master Key must be backed up, stored offline and off-site.
  • V-79215 - Access to database files must be limited to relevant processes and to authorized, administrative users.
  • V-79217 - SQL Server must reveal detailed error messages only to the ISSO, ISSM, SA, and DBA.
  • V-79219 - SQL Server must prevent non-privileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
  • V-79223 - SQL Server must utilize centralized management of the content captured in audit records generated by all components of SQL Server.
  • V-79225 - SQL Server must provide centralized configuration of the content to be captured in audit records generated by all components of SQL Server.
  • V-79229 - SQL Server must provide a warning to appropriate support staff when allocated audit record storage volume reaches 75% of maximum audit record storage capacity.
  • V-79231 - SQL Server must provide an immediate real-time alert to appropriate support staff of all audit log failures.
  • V-79235 - SQL Server must enforce access restrictions associated with changes to the configuration of the instance.
  • V-79237 - Windows must enforce access restrictions associated with changes to the configuration of the SQL Server instance.
  • V-79241 - SQL Server must disable network functions, ports, protocols, and services deemed by the organization to be nonsecure, in accord with the Ports, Protocols, and Services Management (PPSM) guidance.
  • V-79245 - SQL Server services must be configured to run under unique dedicated user accounts.
  • V-79247 - When updates are applied to SQL Server software, any software components that have been replaced or made unnecessary must be removed.
  • V-79249 - Security-relevant software updates to SQL Server must be installed within the time period directed by an authoritative source (e.g. IAVM, CTOs, DTMs, and STIGs).
  • V-79311 - The system SQL Server must off-load audit data to a separate log management facility; this must be continuous and in near real time for systems with a network connection to the storage facility and weekly or more often for stand-alone systems.
  • V-79315 - SQL Server must configure SQL Server Usage and Error Reporting Auditing.
  • V-79355 - When using command-line tools such as SQLCMD in a mixed-mode authentication environment, users must use a logon method that does not expose the password.
  • V-79357 - Applications must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.
Note: The policy engine feature was introduced in SCM 2020.2.1, which is required to use this solution.