UCF STIG Viewer Logo

For those instances where the organization requires encrypted traffic to be visible to information system monitoring tools, the application transmitting the encrypted traffic must make provisions to allow that traffic to be visible to specific system monitoring tool.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35120 SRG-APP-000282-AS-NA SV-46407r1_rule Medium
Description
There is a recognized need to balance encrypting traffic versus the need to have insight into the traffic from a monitoring perspective. For some organizations, the need to ensure the confidentiality of traffic is paramount; for others, the mission-assurance concerns are greater. The AS is not an information system monitoring tool. This requirement does not apply.
STIG Date
Application Server Security Requirements Guide 2013-01-08

Details

Check Text ( C-43509r1_chk )
This requirement is NA for the AS SRG.
Fix Text (F-39673r1_fix)
The requirement is NA. No fix is required.