Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000342-ALG-000093 | SRG-NET-000342-ALG-000093 | SRG-NET-000342-ALG-000093_rule | Medium |
Description |
---|
The use of PIV credentials facilitates standardization and reduces the risk of unauthorized access. DoD has mandated the use of the CAC to support identity management and personal authentication for systems covered under HSPD 12, as well as a primary component of layered protection for national security systems. This requirement applies to ALGs that provide user authentication proxy services. |
STIG | Date |
---|---|
Application Layer Gateway Security Requirements Guide | 2014-06-27 |
Check Text ( C-SRG-NET-000342-ALG-000093_chk ) |
---|
If the ALG does not provide user authentication proxy services, this is not a finding. Examine the ALG configuration to verify the Personal Identity Verification (PIV) credential is electronically verified. If the ALG does not electronically verify Personal Identity Verification (PIV) credentials, this is a finding. |
Fix Text (F-SRG-NET-000342-ALG-000093_fix) |
---|
Configure the ALG to electronically verify Personal Identity Verification (PIV) credentials. |