UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The firewall implementation must use automated mechanisms to enforce access restrictions.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000119-FW-000074 SRG-NET-000119-FW-000074 SRG-NET-000119-FW-000074_rule Medium
Description
Changes to the hardware or software components of the firewall can have significant effects on the overall security of the network. Therefore, the firewall implementation must be configured to use automated mechanisms to enforce access restrictions and prevent unauthorized changes or upgrades to firewall hardware or software. Access restrictions may include the following controls. (i) Physical and logical access controls, workflow automation, and media libraries; (ii) Abstract layers (e.g., changes are implemented using third party interfaces rather than directly onto the firewall); and (iii) Change windows (e.g., changes occur only during specified times, making unauthorized changes easy to discover).
STIG Date
Firewall Security Requirements Guide 2012-12-10

Details

Check Text ( C-SRG-NET-000119-FW-000074_chk )
Verify automated mechanisms are used to enable access restrictions to the hardware and software components of the firewall.

If the firewall implementation does not have automated mechanisms in place to enforce access restrictions, this is a finding.
Fix Text (F-SRG-NET-000119-FW-000074_fix)
Configure the firewall implementation to use automated mechanisms to enforce access restrictions.