UCF STIG Viewer Logo

The IDPS must enforce organizationally defined limitations on the embedding of data types within other data types.


Overview

Finding ID Version Rule ID IA Controls Severity
V-34501 SRG-NET-000031-IDPS-00030 SV-45325r1_rule Medium
Description
Information flow control policies and enforcement mechanisms are commonly employed by organizations to control the flow of information between designated sources and destinations (e.g., networks, individuals, devices) within information systems and between interconnected systems. This control requires limits be set on the number of layers of encapsulation of information. With too many layers, it becomes increasingly difficult to inspect the information for malicious code. Possible enforcement mechanism for IDPS is to create a rule to monitor for and enforce organizationally defined limitations on tunneling and other encapsulation methods.
STIG Date
Intrusion Detection and Prevention Systems (IDPS) Security Requirements Guide 2012-11-19

Details

Check Text ( C-42673r1_chk )
Verify rules exist to enforce network traffic for violations of the organizationally defined limited for encapsulation layers (e.g., tunnels within tunnels).

If the IDPS does not enforce organizationally defined limitations on the embedding of data types within other data types, this is a finding.
Fix Text (F-38721r1_fix)
Create or install a rule which monitors for and enforces violations of the organizationally defined encapsulated limitations.