Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-6677 | KVM01.003.00 | SV-6825r2_rule | PECF-1 PECF-2 | High |
Description |
---|
If the KVM switch is not physically protected in accordance with the requirements of the highest classification for any IS connected to the KVM switch, the KVM switch can be tampered with leading to the compromise of sensitive data or a denial of service caused by the disruption of the systems the KVM switch is connected. The ISSO or SA will ensure the KVM switch is physically protected in accordance with the requirements of the highest classification for any IS connected to the KVM switch. |
STIG | Date |
---|---|
Keyboard Video and Mouse Switch STIG | 2015-06-30 |
Check Text ( C-2605r2_chk ) |
---|
The reviewer will check the location of the KVM switch. If the switch is not located in an area that is secured in the same manner as required of the IS with the highest classification level, then this is a finding. |
Fix Text (F-6259r1_fix) |
---|
Develop a plan to move the KVM switch to a location that is physically protected in accordance with the requirements of the highest classification for any IS connected to the KVM switch. Obtain CM approval for the plan and implement the plan. |