Check: SRG-APP-000473-UEM-000348
Unified Endpoint Management Server SRG:
SRG-APP-000473-UEM-000348
(in versions v2 r3 through v1 r1)
Title
The UEM server must run a suite of self-tests during initial start-up (power on) to demonstrate correct operation of the server. (Cat II impact)
Discussion
Without verification, security functions may not operate correctly and this failure may go unnoticed. Security function is defined as the hardware, software, and/or firmware of the information system responsible for enforcing the system security policy and supporting the isolation of code and data on which the protection is based. Security functionality includes, but is not limited to, establishing system accounts, configuring access authorizations (i.e., permissions, privileges), setting events to be audited, and setting intrusion detection parameters. Notifications provided by information systems include, for example, electronic alerts to system administrators, messages to local computer consoles, and/or hardware indications, such as lights. This requirement applies to applications performing security functions and the applications performing security function verification/testing. Satisfies:FPT_TST_EXT.1.1
Check Content
Verify the UEM server runs a suite of self-tests during initial start-up (power on) to demonstrate correct operation of the server. If the UEM server does not run a suite of self-tests during initial start-up (power on) to demonstrate correct operation of the server, this is a finding.
Fix Text
Configure the UEM server to run a suite of self-tests during initial start-up (power on) to demonstrate correct operation of the server.
Additional Identifiers
Rule ID: SV-234623r961734_rule
Vulnerability ID: V-234623
Group Title: SRG-APP-000473
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002699 |
Perform verification of the correct operation of organization-defined security functions: when the system is in an organization-defined transitional state; upon command by a user with appropriate privileges; and/or on an organization-defined frequency. |
Controls
Number | Title |
---|---|
SI-6 |
Security Function Verification |