UCF STIG Viewer Logo

The firewall implementation must use automated mechanisms to enforce access restrictions.


Overview

Finding ID Version Rule ID IA Controls Severity
V-37114 SRG-NET-000119-FW-000069 SV-48875r1_rule Medium
Description
Changes to the hardware or software components of the firewall can have significant effects on the overall security of the network. Therefore, the firewall implementation must be configured to use automated mechanisms to enforce access restrictions and prevent unauthorized changes or upgrades to firewall hardware or software. Access restrictions may include the following controls. (i) Physical and logical access controls, workflow automation, and media libraries; (ii) Abstract layers (e.g., changes are implemented using third party interfaces rather than directly onto the firewall); and (iii) Change windows (e.g., changes occur only during specified times, making unauthorized changes easy to discover).
STIG Date
Firewall Security Requirements Guide 2013-04-24

Details

Check Text ( C-45486r1_chk )
Verify automated mechanisms are used to enable access restrictions to the hardware and software components of the firewall.

If the firewall implementation does not have automated mechanisms in place to enforce access restrictions, this is a finding.
Fix Text (F-42059r1_fix)
Configure the firewall implementation to use automated mechanisms to enforce access restrictions.