F5 BIG-IP Access Policy Manager 11.x Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
Digest of Updates +18 −23
Comparison against the immediately-prior release (V1R1). Rule matching uses the Group Vuln ID. Content-change detection compares the rule’s description, check, and fix text after stripping inline markup — cosmetic-only edits aren’t flagged.
Added rules 18
- V-215714 Medium The BIG-IP APM module must enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies.
- V-215715 Low The BIG-IP APM module must display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to virtual servers.
- V-215716 Low The BIG-IP APM module must retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users accessing virtual servers acknowledge the usage conditions and take explicit actions to log on for further access.
- V-215717 Low The BIG-IP APM module must display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications.
- V-215718 Medium The BIG-IP APM module must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users) when connecting to virtual servers.
- V-215719 Medium The BIG-IP APM module must be configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or authentication, authorization, and accounting (AAA) server) that validate user account access authorizations and privileges when providing access control to virtual servers.
- V-215720 Medium The BIG-IP APM module must restrict user authentication traffic to specific authentication server(s) when providing user authentication to virtual servers.
- V-215721 Medium The BIG-IP APM module must use multifactor authentication for network access to non-privileged accounts.
- V-215722 Medium The BIG-IP APM module must map the authenticated identity to the user account for PKI-based authentication to virtual servers.
- V-215723 Medium The BIG-IP APM module must be configured to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users) when connecting to virtual servers.
- V-215726 Medium The BIG-IP APM module access policy profile must control remote access methods to virtual servers.
- V-215727 Medium The BIG-IP APM module must require users to re-authenticate when organization-defined circumstances or situations require re-authentication.
- V-215728 Medium The BIG-IP APM module must be configured to require multifactor authentication for remote access with non-privileged accounts to virtual servers in such a way that one of the factors is provided by a device separate from the system gaining access.
- V-215729 Medium The BIG-IP APM module must be configured to require multifactor authentication for remote access with privileged accounts to virtual servers in such a way that one of the factors is provided by a device separate from the system gaining access.
- V-215735 Medium The BIG-IP APM module must conform to FICAM-issued profiles.
- V-215736 Medium The BIG-IP APM module must be configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives.
- V-230211 Medium The BIG-IP APM module access policy profile must be configured to automatically terminate user sessions for users connected to virtual servers when organization-defined conditions or trigger events occur that require a session disconnect.
- V-230212 Medium The BIG-IP APM module access policy profile must be configured to display an explicit logoff message to users, indicating the reliable termination of authenticated communications sessions when disconnecting from virtual servers.
Removed rules 23
- V-59929 Medium The BIG-IP APM module must enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies.
- V-59931 Low The BIG-IP APM module must display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to virtual servers.
- V-59933 Low The BIG-IP APM module must retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users accessing virtual servers acknowledge the usage conditions and take explicit actions to log on for further access.
- V-60025 Low The BIG-IP APM module must display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications.
- V-60027 Medium The BIG-IP APM module must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users) when connecting to virtual servers.
- V-60029 Medium The BIG-IP APM module must be configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or authentication, authorization, and accounting (AAA) server) that validate user account access authorizations and privileges when providing access control to virtual servers.
- V-60031 Medium The BIG-IP APM module must restrict user authentication traffic to specific authentication server(s) when providing user authentication to virtual servers.
- V-60033 Medium The BIG-IP APM module must use multifactor authentication for network access to non-privileged accounts.
- V-60035 Medium The BIG-IP APM module must map the authenticated identity to the user account for PKI-based authentication to virtual servers.
- V-60037 Medium The BIG-IP APM module must be configured to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users) when connecting to virtual servers.
- V-60039 Medium The BIG-IP APM module access policy profile must be configured to automatically terminate user sessions for users connected to virtual servers when organization-defined conditions or trigger events occur that require a session disconnect.
- V-60041 Low The BIG-IP APM module access policy profile must be configured to display an explicit logoff message to users, indicating the reliable termination of authenticated communications sessions when disconnecting from virtual servers.
- V-60043 Medium The BIG-IP APM module access policy profile must control remote access methods to virtual servers.
- V-60045 Medium The BIG-IP APM module must require users to re-authenticate when organization-defined circumstances or situations require re-authentication.
- V-60047 Medium The BIG-IP APM module must be configured to require multifactor authentication for remote access with non-privileged accounts to virtual servers in such a way that one of the factors is provided by a device separate from the system gaining access.
- V-60049 Medium The BIG-IP APM module must be configured to require multifactor authentication for remote access with privileged accounts to virtual servers in such a way that one of the factors is provided by a device separate from the system gaining access.
- V-60051 Medium The BIG-IP APM module must accept Personal Identity Verification (PIV) credentials when providing user authentication to virtual servers.
- V-60053 Medium The BIG-IP APM module must electronically verify Personal Identity Verification (PIV) credentials when providing user authentication to virtual servers.
- V-60055 Medium The BIG-IP APM module must accept Personal Identity Verification (PIV) credentials from other federal agencies.
- V-60057 Medium The BIG-IP APM module must electronically verify Personal Identity Verification (PIV) credentials from other federal agencies.
- V-60059 Medium The BIG-IP APM module must accept FICAM-approved third-party credentials.
- V-60061 Medium The BIG-IP APM module must conform to FICAM-issued profiles.
- V-60063 Medium The BIG-IP APM module must be configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- F5BI-AP-000003
- Vuln IDs
-
- V-215714
- V-59929
- Rule IDs
-
- SV-215714r557355_rule
- SV-74359
Checks: C-16907r290388_chk
If the BIG-IP APM module does not provide user access control intermediary services as part of the traffic management functions of the BIG-IP Core, this is not applicable. Verify the BIG-IP APM module is configured to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles >> Access Profiles List. Review Access Policy Profiles to verify configuration for authorization by employing identity-based, role-based, and/or attribute-based security policies. If the BIG-IP APM is not configured to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies, this is a finding.
Fix: F-16905r290389_fix
If user access control intermediary services are provided as part of the traffic management functions of the BIG-IP Core, configure the BIG-IP APM module to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies.
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000048
- Version
- F5BI-AP-000023
- Vuln IDs
-
- V-215715
- V-59931
- Rule IDs
-
- SV-215715r557355_rule
- SV-74361
Checks: C-16908r290391_chk
If the BIG-IP APM module does not provide user access control intermediary services as part of the traffic management functions of the BIG-IP Core, this is not applicable. Verify the BIG-IP APM module is configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to virtual servers. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access. If the BIG-IP APM module is not configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to the virtual servers, this is a finding.
Fix: F-16906r290392_fix
If user access control intermediary services are provided as part of the traffic management functions of the BIG-IP Core, configure an access policy in the BIG-IP APM module to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to virtual servers.
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000050
- Version
- F5BI-AP-000025
- Vuln IDs
-
- V-215716
- V-59933
- Rule IDs
-
- SV-215716r557355_rule
- SV-74363
Checks: C-16909r290394_chk
If the BIG-IP APM module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and takes explicit actions to log on for further access. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users accessing virtual servers acknowledge the usage conditions and take explicit actions to log on for further access. If the BIG-IP APM module is not configured to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access, this is a finding.
Fix: F-16907r290395_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-001384
- Version
- F5BI-AP-000027
- Vuln IDs
-
- V-215717
- V-60025
- Rule IDs
-
- SV-215717r557355_rule
- SV-74455
Checks: C-16910r290397_chk
If the BIG-IP APM module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications. If the BIG-IP APM module is not configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications, this is a finding.
Fix: F-16908r290398_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- F5BI-AP-000073
- Vuln IDs
-
- V-215718
- V-60027
- Rule IDs
-
- SV-215718r557355_rule
- SV-74457
Checks: C-16911r290400_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). If the BIG-IP APM is not configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users), this is a finding.
Fix: F-16909r290401_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- F5BI-AP-000075
- Vuln IDs
-
- V-215719
- V-60029
- Rule IDs
-
- SV-215719r557355_rule
- SV-74459
Checks: C-16912r290403_chk
If the BIG-IP APM module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or AAA server) that validate user account access authorizations and privileges. If the BIG-IP APM is not configured with a pre-established trust relationship and mechanisms with appropriate authorities that validate each user access authorization and privileges, this is a finding.
Fix: F-16910r290404_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module with a pre-established trust relationship and mechanisms with appropriate authorities that validate each user access authorization and privileges.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- F5BI-AP-000077
- Vuln IDs
-
- V-215720
- V-60031
- Rule IDs
-
- SV-215720r557355_rule
- SV-74461
Checks: C-16913r290406_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to restrict user authentication traffic to specific authentication server(s). If the BIG-IP APM module is not configured to restrict user authentication traffic to a specific authentication server(s), this is a finding.
Fix: F-16911r290407_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to restrict user authentication traffic to specific authentication server(s).
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000766
- Version
- F5BI-AP-000079
- Vuln IDs
-
- V-215721
- V-60033
- Rule IDs
-
- SV-215721r557355_rule
- SV-74463
Checks: C-16914r290409_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM is configured to use multifactor authentication for network access to non-privileged accounts. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to use multifactor authentication for network access to non-privileged accounts. If the BIG-IP APM module is not configured to use multifactor authentication for network access to non-privileged accounts, this is a finding.
Fix: F-16912r290410_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to use multifactor authentication for network access to non-privileged accounts.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- F5BI-AP-000085
- Vuln IDs
-
- V-215722
- V-60035
- Rule IDs
-
- SV-215722r557355_rule
- SV-74465
Checks: C-16915r290412_chk
If the BIG-IP APM module does not provide PKI-based, user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module maps the authenticated identity to the user account for PKI-based authentication. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for PKI-based authentication. Verify the Access Profile is configured to map the authenticated identity to the user account for PKI-based authentication. If the BIG-IP APM module does not map the authenticated identity to the user account for PKI-based authentication, this is a finding.
Fix: F-16913r290413_fix
If the BIG-IP APM module provides PKI-based, user authentication intermediary services, configure a profile in the BIG-IP APM module to map the authenticated identity to the user account for PKI-based authentication.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- F5BI-AP-000087
- Vuln IDs
-
- V-215723
- V-60037
- Rule IDs
-
- SV-215723r557355_rule
- SV-74467
Checks: C-16916r290415_chk
If the BIG-IP APM module does not provide user authentication intermediary services to non-organizational users, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used to identify and authenticate non-organizational users. Verify the Access Profile is configured to uniquely identify and authenticate non-organizational users. If the BIG-IP APM module is not configured to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users) when connecting to virtual servers, this is a finding.
Fix: F-16914r290416_fix
If the BIG-IP APM module provides user authentication intermediary services to non-organizational users, configure a profile in the BIG-IP APM module to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users) when connecting to virtual servers.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- F5BI-AP-000153
- Vuln IDs
-
- V-215726
- V-60043
- Rule IDs
-
- SV-215726r557355_rule
- SV-74473
Checks: C-16919r290424_chk
If the BIG-IP APM module does not serve as an intermediary for remote access traffic (e.g., web content filter, TLS and webmail), this is not applicable. Verify the BIG-IP APM module is configured to control remote access methods. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for managing remote access. Verify the Access Profile is configured to control remote access methods. If the BIG-IP APM module is not configured to control remote access methods, this is a finding.
Fix: F-16917r290425_fix
If intermediary services for remote access communications traffic are provided, configure the BIG-IP APM module to control remote access methods.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- F5BI-AP-000191
- Vuln IDs
-
- V-215727
- V-60045
- Rule IDs
-
- SV-215727r557355_rule
- SV-74475
Checks: C-16920r290427_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for organizational access. Verify the Access Profile is configured to require users to re-authenticate when organization-defined circumstances or situations require re-authentication. If the BIG-IP APM module is not configured to require users to re-authenticate when organization-defined circumstances or situations require re-authentication, this is a finding.
Fix: F-16918r290428_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to require users to re-authenticate when organization-defined circumstances or situations require re-authentication.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001951
- Version
- F5BI-AP-000193
- Vuln IDs
-
- V-215728
- V-60047
- Rule IDs
-
- SV-215728r557355_rule
- SV-74477
Checks: C-16921r290430_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for remote access for non-privileged accounts. Verify the Access Profile is configured to require multifactor authentication for remote access with non-privileged accounts. If the BIG-IP APM module is not configured to require multifactor authentication for remote access to non-privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access, this is a finding.
Fix: F-16919r290431_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to require multifactor authentication for remote access to non-privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001948
- Version
- F5BI-AP-000195
- Vuln IDs
-
- V-215729
- V-60049
- Rule IDs
-
- SV-215729r557355_rule
- SV-74479
Checks: C-16922r290433_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for remote access for privileged accounts. Verify the Access Profile is configured to require multifactor authentication for remote access with privileged accounts. If the BIG-IP APM module is not configured to require multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access, this is a finding.
Fix: F-16920r290434_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to require multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-002014
- Version
- F5BI-AP-000211
- Vuln IDs
-
- V-215735
- V-60061
- Rule IDs
-
- SV-215735r557355_rule
- SV-74491
Checks: C-16928r290451_chk
If the BIG-IP APM module does not provide user authentication intermediary services to non-organizational users, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used to identify and authenticate non-organizational users. Verify the Access Profile is configured to conform to FICAM-issued profiles. If the BIG-IP APM module is not configured to conform to FICAM-issued profiles, this is a finding.
Fix: F-16926r290452_fix
If the BIG-IP APM module provides user authentication intermediary services to non-organizational users, configure a profile in the BIG-IP APM module that conforms to FICAM-issued profiles.
- RMF Control
- SI-10
- Severity
- M
- CCI
- CCI-002754
- Version
- F5BI-AP-000229
- Vuln IDs
-
- V-215736
- V-60063
- Rule IDs
-
- SV-215736r557355_rule
- SV-74493
Checks: C-16929r290454_chk
Verify the BIG-IP APM module is configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives. This can be demonstrated by the SA sending an invalid input to a virtual server. Provide evidence that the virtual server was able to handle the invalid input and maintain operation. If the BIG-IP APM module is not configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives, this is a finding.
Fix: F-16927r290455_fix
Configure the BIG-IP APM module to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002361
- Version
- F5BI-AP-000147
- Vuln IDs
-
- V-230211
- V-60039
- Rule IDs
-
- SV-230211r561151_rule
- SV-74469
Checks: C-16917r290418_chk
If the BIG-IP Am module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for organizational access. Verify the Access Profile is configured to automatically terminate user sessions when organization-defined conditions or trigger events occur that require a session disconnect. If the BIG-IP APM module is not configured to automatically terminate a user session when organization-defined conditions or trigger events occur that require a session disconnect, this is a finding.
Fix: F-16915r290419_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to automatically terminate a user session when organization-defined conditions or trigger events occur that require a session disconnect.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002364
- Version
- F5BI-AP-000151
- Vuln IDs
-
- V-230212
- V-60041
- Rule IDs
-
- SV-230212r561153_rule
- SV-74471
Checks: C-32546r561152_chk
If the BIG-IP APM module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for connecting to virtual servers. Verify the Access Profile is configured to display an explicit logoff message to users, indicating the reliable termination of authenticated communications sessions. If the BIG-IP APM module is not configured to display an explicit logoff message to users indicating the reliable termination of authenticated communications sessions, this is a finding.
Fix: F-16916r290422_fix
If user access control intermediary services are provided, configure the BIG-IP APM module to display an explicit logoff message to users indicating the reliable termination of authenticated communications sessions.