Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000221-IDPS-000170 | SRG-NET-000221-IDPS-000170 | SRG-NET-000221-IDPS-000170_rule | Medium |
Description |
---|
Whether a network is being managed locally or from a Network Operations Center (NOC), achieving network management objectives depends on comprehensive and reliable network management solutions. To protect the integrity and confidentiality of non-local maintenance and diagnostics, all packets associated with these sessions must be encrypted. During the authentication process, malicious users can gain knowledge of passwords during authentication process by sniffing local traffic between the IDPS and the authentication server. It is imperative the authentication process and the transmission of network management traffic implements NSA-approved cryptography. |
STIG | Date |
---|---|
IDPS Security Requirements Guide (SRG) | 2012-03-08 |
Check Text ( C-43310_chk ) |
---|
Inspect the encryption configuration function. Verify NSA-approved, type 1 encryption is used to protect information in transit and in storage. If the system is not configured to use NSA-approved, type 1 cryptography to protect classified information, this is a finding. |
Fix Text (F-43310_fix) |
---|
Configure the IDPS to use NSA-approved, type 1 cryptography to protect classified information. |