Best Practices Checklist

The System Administration > Best Practices Checklist menu displays how the current server configuration aligns with the selected Best Practices Settings. The page shows the current score, checklist pass rates, and detailed results for each check.

The page contains three sections:

  • Best Practices Settings: Displays the checklists currently included in the report. Depending on your settings, you can select:

    • Imprivata: Imprivata's recommendations for safety and security.

    • HIPAA: Health Insurance Portability and Accountability Act
      Learn more about HIPAA.

    • PCI: Payment Card Industry
      Learn more about PCI.

    • NERC: North American Electric Reliability Corporation
      Learn more about NERC.

    • CJIS: Criminal Justice Information Services (FBI)
      Learn more about CJIS.

    • NIST: National Institute of Standards and Technology
      Learn more about NIST.

  • Overall Score: Summarizes the current report status, based on the checklists you select and your server's configuration.
    Click Accept Score to accept the current score as the minimum accepted score for the server. If the score later falls below that accepted score, the system can send notification emails to the configured notification list.

  • Best Practices Checklist: Provides a table with all the checklists you select in the settings and their statuses.

Checklist Reference

Use the following table to learn which checklist suits your needs best.

Checklist Category Check Description
Imprivata, PCI, NERC, CJIS Architecture Audit Retention Period Checks whether audit data is kept for the retention period required by the selected checklist.
Imprivata, HIPAA, PCI Architecture Client Anti-virus Health Checks whether Windows client anti-virus health is enforced at the required level.
Imprivata, HIPAA, PCI, NIST Architecture Disaster Recovery Checks whether disaster recovery is configured and available.
Imprivata, CJIS Architecture FIPS 140-2 Encryption Enabled Checks whether FIPS 140-2 encryption is enforced.
Imprivata Architecture Notification List Checks whether a notification list is configured for score-drop alerts.
Imprivata, PCI, CJIS Architecture NTP Synchronization Checks whether network time synchronization is configured.
Imprivata Architecture Redundant Gateways Checks whether gateways are pooled or have redundant instances.
Imprivata Architecture Redundant SMTP Checks whether more than one SMTP server is configured.
Imprivata, HIPAA, PCI, NERC, CJIS, NIST Architecture SSL Certificate Expiration Checks whether the server certificate is valid and not expired.
Imprivata Architecture Version Checks whether the server version is recent enough to stay within the supported window.
Imprivata, HIPAA, PCI, CJIS Architecture Transmission Encryption Checks whether connection encryption meets the selected checklist requirements.
Imprivata Authentication AD/SSO Integration Checks whether Active Directory or single sign-on is configured.
Imprivata, PCI, NERC, CJIS Authentication Authentication Failure Lockout Checks whether failed logins trigger lockout and whether the threshold meets checklist rules.
Imprivata Authentication Credential Passthrough Checks whether eligible services use credential passthrough or have a credential attached.
Imprivata, PCI, CJIS, NIST Authentication Two-Factor Authentication for internal users Checks whether multi-factor authentication is enforced for internal users.
Imprivata, PCI, NERC Authentication Password Character Set Checks whether password complexity requires the needed mix of character types.
Imprivata, CJIS, NIST Authentication Password Dictionary Check Checks whether common or dictionary passwords are blocked.
Imprivata, PCI, NERC, CJIS Authentication Password Expiration Checks whether password expiration is set within the required limit.
Imprivata, PCI, CJIS Authentication Password history restriction Checks whether password reuse is limited by remembered history.
Imprivata, PCI, NERC, CJIS, NIST Authentication Password Length Checks whether the minimum password length meets checklist rules.
Imprivata, PCI, CJIS, NIST Authorization Terms and Conditions Checks whether vendor terms and conditions are enabled and configured.
Imprivata, HIPAA, PCI, CJIS, NIST Authorization Inactive Accounts Expiration Checks whether inactive internal accounts are disabled within the required time.
Imprivata Authorization Inactive Applications Checks whether inactive applications without access expiration are identified.
Imprivata, HIPAA, PCI, CJIS, NIST Authorization Inactive Vendor Accounts Checks whether inactive vendor accounts expire within the required time.
Imprivata, HIPAA, PCI, NERC, CJIS, NIST Authorization Minimum Access Windows Checks whether applications avoid unlimited or permanently enabled access.
Imprivata Authorization Public Domains Checks whether vendor representatives use public-domain email addresses.
Imprivata, HIPAA, PCI, CJIS, NIST Authorization Session Expiration Checks whether idle session timeout is configured within the required limit.
Imprivata Configuration Support Contact Information Checks whether support contact information is configured.
Imprivata Identification Domain Restrictions Checks whether restricted or generic email domains are blocked where required.
Imprivata, HIPAA Identification External Employment Verification Checks whether external or vendor access uses email verification where required.
Imprivata, HIPAA Identification Internal Employment Verification Checks whether internal users are protected by email verification or by Active Directory/single sign-on where required.
Imprivata, HIPAA, PCI, CJIS Identification Unique User IDs Checks whether shared user IDs are absent.