UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

The firewall implementation must use cryptographic mechanisms to protect the integrity of information while in transit, unless otherwise protected by alternative physical measures.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000208-FW-000132 SRG-NET-000208-FW-000132 SRG-NET-000208-FW-000132_rule Medium
Description
This control applies to communications across internal and external networks, unless the information is protected by a physical security solution (e.g., PDS or physical access control) while in transit. The firewall implementation must employ cryptographic mechanisms to recognize changes to information during transmission unless the transmission is otherwise protected by alternative physical measures. If connectivity is provided by a commercial service provider rather than a dedicated service, obtaining the necessary assurances regarding the implementation of needed security controls for transmission integrity may not be possible. Without cryptographic integrity controls, information traveling over commercial networks could be altered or compromised during transmission. Therefore, these controls must be obtained from the service provider using appropriate contracting vehicles. If this is not feasible, then the organization will implement physical or logical compensating security controls.
STIG Date
Firewall Security Requirements Guide 2012-12-10

Details

Check Text ( C-SRG-NET-000208-FW-000132_chk )
This control does not apply if the information is protected by a physical security solution (e.g., PDS or physical access control) while in transit.

Inspect the encryption configuration for each configured interface.
Verify the encryption module is configured to use an approved hashing algorithm to protect information in transit through all interfaces capable of transmitting information.

If the firewall implementation does not use cryptographic mechanisms to protect the integrity of information while in transit, this is a finding.
Fix Text (F-SRG-NET-000208-FW-000132_fix)
Configure the cryptographic module on all interfaces capable of communications to use cryptographic mechanisms configured with an approved hashing algorithm to protect the integrity of information while in transit.