UCF STIG Viewer Logo

The IDPS must employ NSA-approved cryptography to protect classified information.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000221-IDPS-000170 SRG-NET-000221-IDPS-000170 SRG-NET-000221-IDPS-000170_rule Medium
Description
Whether a network is being managed locally or from a Network Operations Center (NOC), achieving network management objectives depends on comprehensive and reliable network management solutions. To protect the integrity and confidentiality of non-local maintenance and diagnostics, all packets associated with these sessions must be encrypted. During the authentication process, malicious users can gain knowledge of passwords during authentication process by sniffing local traffic between the IDPS and the authentication server. It is imperative the authentication process and the transmission of network management traffic implements NSA-approved cryptography.
STIG Date
IDPS Security Requirements Guide (SRG) 2012-03-08

Details

Check Text ( C-43310_chk )
Inspect the encryption configuration function.
Verify NSA-approved, type 1 encryption is used to protect information in transit and in storage.

If the system is not configured to use NSA-approved, type 1 cryptography to protect classified information, this is a finding.
Fix Text (F-43310_fix)
Configure the IDPS to use NSA-approved, type 1 cryptography to protect classified information.