Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-6757 | KVM04.004.00 | SV-6979r1_rule | DCBP-1 | Medium |
Description |
---|
When using a KVM switch to switch a peripheral between two or more users the risk always exists where the peripheral is connected to the wrong IS. An example would be a scanner where the user presses a button on the scanner which causes the IS the scanner is currently to initiate a scan. If the A/B is pointed to a different IS than the user intended the document would be scanned into the wrong system. This could lead to the compromise of sensitive data. The IAO or SA will ensure that an A/B switch is not used to share a peripheral device between two or more users. |
STIG | Date |
---|---|
Keyboard Video and Mouse Switch STIG | 2014-08-04 |
Check Text ( C-2899r1_chk ) |
---|
The reviewer will interview the IAO or SA to verify that A/B switches are not being used to share peripherals between two users. |
Fix Text (F-6405r1_fix) |
---|
Develop a plan to remove all A/B switches that are being used to switch peripherals between two or more users and to acquire new peripherals to support documented needs. Obtain CM approval of the plan and execute the plan. |