Check: BROM-00-000005
Bromium Secure Platform 4.x STIG:
BROM-00-000005
(in version v1 r1)
Title
The Bromium Enterprise Controller (BEC) must set the number of concurrent sessions to 1. (Cat II impact)
Discussion
Application management includes the ability to control the number of users and user sessions that utilize an application. Limiting the number of allowed users and sessions per user is helpful in limiting risks related to denial-of-service (DoS) attacks. This requirement addresses concurrent sessions for information system accounts and does not address concurrent sessions by single users via multiple system accounts. The maximum number of concurrent sessions should be defined based on mission needs and the operational environment for each system. Edit the BEC configuration file (C:\ProgramData\Bromium\BMS\settings.json) to set the concurrent session parameter. The options are "unlimited" and "1". Unlimited is not a valid selection in DoD.
Check Content
Inspect the configuration file on the BEC. BEC configuration file (C:\ProgramData\Bromium\BMS\settings.json). Verify the concurrent session parameter is set to "1". If the BEC concurrent session parameter is not set to "1", this is a finding.
Fix Text
Edit the BEC configuration file (C:\ProgramData\Bromium\BMS\settings.json) to set the concurrent session parameter to "1".
Additional Identifiers
Rule ID: SV-95127r1_rule
Vulnerability ID: V-80423
Group Title: SRG-APP-000001
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000054 |
The information system limits the number of concurrent sessions for each organization-defined account and/or account type to an organization-defined number of sessions. |
Controls
Number | Title |
---|---|
AC-10 |
Concurrent Session Control |