Best Practices Checklist
The System Administration > Best Practices Checklist menu displays how the current server configuration aligns with the selected Best Practices Settings. The page shows the current score, checklist pass rates, and detailed results for each check.
The page contains three sections:
-
Best Practices Settings: Displays the checklists currently included in the report. Depending on your settings, you can select:
-
Imprivata: Imprivata's recommendations for safety and security.
-
HIPAA: Health Insurance Portability and Accountability Act
Learn more about HIPAA. -
PCI: Payment Card Industry
Learn more about PCI. -
NERC: North American Electric Reliability Corporation
Learn more about NERC. -
CJIS: Criminal Justice Information Services (FBI)
Learn more about CJIS. -
NIST: National Institute of Standards and Technology
Learn more about NIST.
-
-
Overall Score: Summarizes the current report status, based on the checklists you select and your server's configuration.
Click Accept Score to accept the current score as the minimum accepted score for the server. If the score later falls below that accepted score, the system can send notification emails to the configured notification list. -
Best Practices Checklist: Provides a table with all the checklists you select in the settings and their statuses.
Checklist Reference
Use the following table to learn which checklist suits your needs best.
| Checklist | Category | Check | Description |
|---|---|---|---|
| Imprivata, PCI, NERC, CJIS | Architecture | Audit Retention Period | Checks whether audit data is kept for the retention period required by the selected checklist. |
| Imprivata, HIPAA, PCI | Architecture | Client Anti-virus Health | Checks whether Windows client anti-virus health is enforced at the required level. |
| Imprivata, HIPAA, PCI, NIST | Architecture | Disaster Recovery | Checks whether disaster recovery is configured and available. |
| Imprivata, CJIS | Architecture | FIPS 140-2 Encryption Enabled | Checks whether FIPS 140-2 encryption is enforced. |
| Imprivata | Architecture | Notification List | Checks whether a notification list is configured for score-drop alerts. |
| Imprivata, PCI, CJIS | Architecture | NTP Synchronization | Checks whether network time synchronization is configured. |
| Imprivata | Architecture | Redundant Gateways | Checks whether gateways are pooled or have redundant instances. |
| Imprivata | Architecture | Redundant SMTP | Checks whether more than one SMTP server is configured. |
| Imprivata, HIPAA, PCI, NERC, CJIS, NIST | Architecture | SSL Certificate Expiration | Checks whether the server certificate is valid and not expired. |
| Imprivata | Architecture | Version | Checks whether the server version is recent enough to stay within the supported window. |
| Imprivata, HIPAA, PCI, CJIS | Architecture | Transmission Encryption | Checks whether connection encryption meets the selected checklist requirements. |
| Imprivata | Authentication | AD/SSO Integration | Checks whether Active Directory or single sign-on is configured. |
| Imprivata, PCI, NERC, CJIS | Authentication | Authentication Failure Lockout | Checks whether failed logins trigger lockout and whether the threshold meets checklist rules. |
| Imprivata | Authentication | Credential Passthrough | Checks whether eligible services use credential passthrough or have a credential attached. |
| Imprivata, PCI, CJIS, NIST | Authentication | Two-Factor Authentication for internal users | Checks whether multi-factor authentication is enforced for internal users. |
| Imprivata, PCI, NERC | Authentication | Password Character Set | Checks whether password complexity requires the needed mix of character types. |
| Imprivata, CJIS, NIST | Authentication | Password Dictionary Check | Checks whether common or dictionary passwords are blocked. |
| Imprivata, PCI, NERC, CJIS | Authentication | Password Expiration | Checks whether password expiration is set within the required limit. |
| Imprivata, PCI, CJIS | Authentication | Password history restriction | Checks whether password reuse is limited by remembered history. |
| Imprivata, PCI, NERC, CJIS, NIST | Authentication | Password Length | Checks whether the minimum password length meets checklist rules. |
| Imprivata, PCI, CJIS, NIST | Authorization | Terms and Conditions | Checks whether vendor terms and conditions are enabled and configured. |
| Imprivata, HIPAA, PCI, CJIS, NIST | Authorization | Inactive Accounts Expiration | Checks whether inactive internal accounts are disabled within the required time. |
| Imprivata | Authorization | Inactive Applications | Checks whether inactive applications without access expiration are identified. |
| Imprivata, HIPAA, PCI, CJIS, NIST | Authorization | Inactive Vendor Accounts | Checks whether inactive vendor accounts expire within the required time. |
| Imprivata, HIPAA, PCI, NERC, CJIS, NIST | Authorization | Minimum Access Windows | Checks whether applications avoid unlimited or permanently enabled access. |
| Imprivata | Authorization | Public Domains | Checks whether vendor representatives use public-domain email addresses. |
| Imprivata, HIPAA, PCI, CJIS, NIST | Authorization | Session Expiration | Checks whether idle session timeout is configured within the required limit. |
| Imprivata | Configuration | Support Contact Information | Checks whether support contact information is configured. |
| Imprivata | Identification | Domain Restrictions | Checks whether restricted or generic email domains are blocked where required. |
| Imprivata, HIPAA | Identification | External Employment Verification | Checks whether external or vendor access uses email verification where required. |
| Imprivata, HIPAA | Identification | Internal Employment Verification | Checks whether internal users are protected by email verification or by Active Directory/single sign-on where required. |
| Imprivata, HIPAA, PCI, CJIS | Identification | Unique User IDs | Checks whether shared user IDs are absent. |