STIGhubSTIGhub
STIGsSearchCompareAbout

STIGhub

A free tool to search and browse the entire DISA STIG library. Saves up to 75% in security compliance research time.

Navigation

  • Browse STIGs
  • Search
  • Compare Versions

Resources

  • About
  • VPAT
  • DISA STIG Library
STIGs updated 2 hours ago
Powered by Pylon
© 2026 Beacon Cloud Solutions, Inc. All rights reserved.
← Back to STIGs

HP FlexFabric Switch NDM Security Technical Implementation Guide

Version

V1R4

Release Date

Jun 12, 2025

SCAP Benchmark ID

HP_FlexFabric_Switch_NDM_STIG

Total Checks

79

Tags

network
CAT I: 2CAT II: 64CAT III: 13

This Security Technical Implementation Guide is published as a tool to improve the security of Department of Defense (DOD) information systems. The requirements are derived from the National Institute of Standards and Technology (NIST) 800-53 and related documents. Comments or proposed revisions to this document should be sent via e-mail to the following address: disa.stig_spt@mail.mil.

Export CKLExport CSVExport JSONDownload STIG ZIP

Checks (79)

V-217426LOWThe HP FlexFabric Switch must limit the number of concurrent sessions to an organization-defined number for each administrator account and/or administrator account type.V-217427MEDIUMThe HP FlexFabric Switch must automatically audit account creation.V-217428MEDIUMThe HP FlexFabric Switch must automatically audit account modification.V-217429MEDIUMThe HP FlexFabric Switch must automatically audit account disabling actions.V-217430MEDIUMThe HP FlexFabric Switch must automatically audit account removal actions.V-217431HIGHThe HP FlexFabric Switch must enforce the assigned privilege level for each administrator and authorizations for access to all commands relative to the privilege level in accordance with applicable policy for the device.V-217432MEDIUMThe HP FlexFabric Switch must enforce approved authorizations for controlling the flow of management information within the HP FlexFabric Switch based on information flow control policies.V-217433MEDIUMThe HP FlexFabric Switch must enforce the limit of three consecutive invalid logon attempts by a user during a 15-minute time period.V-217434MEDIUMThe HP FlexFabric Switch must display the Standard Mandatory DoD Notice and Consent Banner before granting access to the device.V-217435MEDIUMThe HP FlexFabric Switch must retain the Standard Mandatory DoD Notice and Consent Banner on the screen until the administrator acknowledges the usage conditions and takes explicit actions to log on for further access.V-217436LOWThe HP FlexFabric Switch must protect against an individual (or process acting on behalf of an individual) falsely denying having performed organization-defined actions to be covered by non-repudiation.V-217438MEDIUMThe HP FlexFabric Switch must generate audit records when successful/unsuccessful attempts to access privileges occur.V-217439LOWThe HP FlexFabric Switch must initiate session auditing upon startup.V-217440LOWThe HP FlexFabric Switch must produce audit log records containing sufficient information to establish what type of event occurred.V-217441LOWThe HP FlexFabric Switch must produce audit records containing information to establish when (date and time) the events occurred.V-217442LOWThe HP FlexFabric Switch must produce audit records containing information to establish where the events occurred.V-217443LOWThe HP FlexFabric Switch must produce audit log records containing information to establish the source of events.V-217444LOWThe HP FlexFabric Switch must produce audit records that contain information to establish the outcome of the event.V-217445LOWThe HP FlexFabric Switch must generate audit records containing information that establishes the identity of any individual or process associated with the event.V-217446LOWThe HP FlexFabric Switch must generate audit records containing the full-text recording of privileged commands.V-217447MEDIUMThe HP FlexFabric Switch must use internal system clocks to generate time stamps for audit records.V-217448MEDIUMThe HP FlexFabric Switch must protect audit information from unauthorized modification.V-217449MEDIUMThe HP FlexFabric Switch must protect audit information from unauthorized deletion.V-217451MEDIUMThe HP FlexFabric Switch must be configured to prohibit the use of all unnecessary and/or nonsecure functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.V-217452MEDIUMThe HP FlexFabric Switch must enforce a minimum 15-character password length.V-217453MEDIUMIf multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one uppercase character be used.V-217454MEDIUMIf multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one lowercase character be used.V-217455MEDIUMIf multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one numeric character be used.V-217456MEDIUMIf multifactor authentication is not supported and passwords must be used, the HP FlexFabric Switch must enforce password complexity by requiring that at least one special character be used.V-217457MEDIUMThe HP FlexFabric Switch must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after 10 minutes of inactivity except to fulfill documented and validated mission requirements.V-217458MEDIUMNetwork devices must provide a logoff capability for administrator-initiated communication sessions.V-217459MEDIUMThe HP FlexFabric Switch must automatically audit account enabling actions.V-217460MEDIUMIf the HP FlexFabric Switch uses discretionary access control, the HP FlexFabric Switch must enforce organization-defined discretionary access control policies over defined subjects and objects.V-217461MEDIUMIf the HP FlexFabric Switch uses role-based access control, the HP FlexFabric Switch must enforce organization-defined role-based access control policies over defined subjects and objects.V-217463MEDIUMThe HP FlexFabric Switch must allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.V-217464MEDIUMThe HP FlexFabric Switch must generate an immediate real-time alert of all audit failure events requiring real-time alerts.V-217465MEDIUMThe HP FlexFabric Switch must be configured to synchronize internal information system clocks with the primary and secondary time sources located in different geographic regions using redundant authoritative time sources.V-217466MEDIUMThe HP FlexFabric Switch must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT).V-217467MEDIUMThe HP FlexFabric Switch must record time stamps for audit records that meet a granularity of one second for a minimum degree of precision.V-217468MEDIUMApplications used for nonlocal maintenance sessions must implement cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.V-217469MEDIUMApplications used for nonlocal maintenance sessions must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.V-217470MEDIUMThe HP FlexFabric Switch must protect against or limit the effects of all known types of Denial of Service (DoS) attacks on the HP FlexFabric Switch management network by employing organization-defined security safeguards.V-217471MEDIUMIf the HP FlexFabric Switch uses mandatory access control, the HP FlexFabric Switch must enforce organization-defined mandatory access control policies over all subjects and objects.V-217472MEDIUMThe HP FlexFabric Switch must generate audit records when successful/unsuccessful attempts to modify administrator privileges occur.V-217473MEDIUMThe HP FlexFabric Switch must generate audit records when successful/unsuccessful attempts to delete administrator privileges occur.V-217474MEDIUMThe HP FlexFabric Switch must generate audit records when successful/unsuccessful logon attempts occur.V-217475MEDIUMThe HP FlexFabric Switch must generate audit records for privileged activities or other system-level access.V-217476MEDIUMThe HP FlexFabric Switch must generate audit records showing starting and ending time for administrator access to the system.V-217477MEDIUMThe HP FlexFabric Switch must generate audit records when concurrent logons from different workstations occur.V-217478MEDIUMThe HP FlexFabric Switch must off-load audit records onto a different system or media than the system being audited.V-217479MEDIUMThe HP FlexFabric Switch must generate audit log events for a locally developed list of auditable events.V-217480MEDIUMThe HP FlexFabric Switch must enforce access restrictions associated with changes to the system components.V-217481LOWThe HP FlexFabric Switch must support organizational requirements to conduct backups of system level information contained in the information system when changes occur or weekly, whichever is sooner.V-217482MEDIUMThe HP FlexFabric Switch must obtain its public key certificates from an appropriate certificate policy through an approved service provider.V-217483HIGHThe HP FlexFabric Switch must have a local account that will only be used as an account of last resort with full access to the network device.V-217484MEDIUMThe HP FlexFabric switch must be configured to utilize an authentication server for the purpose of authenticating privilege users, managing accounts, and to centrally verify authentication settings and Personal Identity Verification (PIV) credentials.V-217485MEDIUMThe HP FlexFabric switch must be configured to send log data to a syslog server for the purpose of forwarding alerts to the administrators and the ISSO.V-217486MEDIUMThe HP FlexFabric switch must be configured to send SNMP traps and notifications to the SNMP manager for the purpose of sending alarms and notifying appropriate personnel as required by specific events.V-230161LOWThe HP FlexFabric Switch must automatically disable accounts after a 35-day period of account inactivity.V-230162MEDIUMUpon successful logon, the HP FlexFabric Switch must notify the administrator of the date and time of the last logon.V-230163MEDIUMUpon successful logon, the HP FlexFabric Switch must notify the administrator of the number of unsuccessful logon attempts since the last successful logon.V-230164LOWThe HP FlexFabric Switch must provide audit record generation capability for DoD-defined auditable events within the HP FlexFabric Switch.V-230165MEDIUMThe HP FlexFabric Switch must protect audit information from any type of unauthorized read access.V-230166MEDIUMThe HP FlexFabric Switch must disable identifiers (individuals, groups, roles, and devices) after 35 days of inactivity.V-230167MEDIUMThe HP FlexFabric Switch must prohibit password reuse for a minimum of five generations.V-230168MEDIUMThe HP FlexFabric Switch must enforce 24 hours/1 day as the minimum password lifetime.V-230169MEDIUMThe HP FlexFabric Switch must enforce a 60-day maximum password lifetime restriction.V-230170MEDIUMThe HP FlexFabric Switch, when utilizing PKI-based authentication, must validate certificates by constructing a certification path (which includes status information) to an accepted trust anchor.V-230171MEDIUMThe HP FlexFabric Switch must map the authenticated identity to the user account for PKI-based authentication.V-230172MEDIUMThe HP FlexFabric Switch must generate an immediate alert for account enabling actions.V-230173MEDIUMThe HP FlexFabric Switch must automatically lock the account until the locked account is released by an administrator when three unsuccessful logon attempts in 15 minutes are exceeded.V-230174MEDIUMThe HP FlexFabric Switch must notify the administrator, upon successful logon (access), of the location of last logon (terminal or IP address) in addition to the date and time of the last logon (access).V-230175MEDIUMThe HP FlexFabric Switch must generate an immediate alert when allocated audit record storage volume reaches 75% of repository maximum audit record storage capacity.V-230176MEDIUMThe HP FlexFabric Switch must compare internal information system clocks at least every 24 hours with an authoritative time server.V-230177MEDIUMThe HP FlexFabric Switch must synchronize internal information system clocks to the authoritative time source when the time difference is greater than the organization-defined time period.V-230178MEDIUMThe HP FlexFabric Switch must allow the use of a temporary password for system logons with an immediate change to a permanent password.V-230179MEDIUMThe HP FlexFabric Switch must generate audit records for all account creations, modifications, disabling, and termination events.V-230180MEDIUMThe HP FlexFabric Switch must notify the administrator of the number of successful logon attempts occurring during an organization-defined time period.V-230181MEDIUMThe HP FlexFabric Switch must employ automated mechanisms to assist in the tracking of security incidents.