UCF STIG Viewer Logo

For authenticated, proxied connections, the ALG must electronically verify Personal Identity Verification (PIV) credentials.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000342-ALG-000093 SRG-NET-000342-ALG-000093 SRG-NET-000342-ALG-000093_rule Medium
Description
The use of PIV credentials facilitates standardization and reduces the risk of unauthorized access. DoD has mandated the use of the CAC to support identity management and personal authentication for systems covered under HSPD 12, as well as a primary component of layered protection for national security systems. This requirement applies to ALGs that provide user authentication proxy services.
STIG Date
Application Layer Gateway Security Requirements Guide 2014-06-27

Details

Check Text ( C-SRG-NET-000342-ALG-000093_chk )
If the ALG does not provide user authentication proxy services, this is not a finding.

Examine the ALG configuration to verify the Personal Identity Verification (PIV) credential is electronically verified.

If the ALG does not electronically verify Personal Identity Verification (PIV) credentials, this is a finding.
Fix Text (F-SRG-NET-000342-ALG-000093_fix)
Configure the ALG to electronically verify Personal Identity Verification (PIV) credentials.