UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The firewall implementation must implement organizationally defined nondiscretionary access control policies over organizationally defined users and resources.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000017-FW-000016 SRG-NET-000017-FW-000016 SRG-NET-000017-FW-000016_rule Low
Description
When nondiscretionary access control mechanisms are implemented, security labels are assigned to securable objects and users are granted access to the objects only if their level of access matches that required by the security label. Types of nondiscretionary access control include Attribute-Based Access Control, Mandatory Access Control, and Originator Controlled Access Control. Without these security policies, security labels on restricted objects stored on the firewall may be accessed or changed by unauthorized users.
STIG Date
Firewall Security Requirements Guide 2012-12-10

Details

Check Text ( C-SRG-NET-000017-FW-000016_chk )
Verify the firewall is configured to implement access control by assigning rights and permissions to users and resources.

If the firewall is not configured with rights and permissions for users and resources, this is a finding.
Fix Text (F-SRG-NET-000017-FW-000016_fix)
Configure the firewall implementation using nondiscretionary access control as required by organizationally defined policies.