Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-6685 | KVM02.001.00 | SV-6847r2_rule | DCHW-1 | Low |
Description |
---|
Without a written description of the KVM switch, the ISs attached to the KVM switch, and the classification level of each IS attached to the KVM switch, tampering with the KVM switch by adding or moving connections cannot be verified and the physical configuration cannot be reproduced if needed. This can lead to a denial of service or a compromise of sensitive data if a connection is removed, moved, or added. The ISSO will maintain a written description of the KVM switch, the ISs attached to the KVM switch, and the classification level of each IS attached to the KVM switch. |
STIG | Date |
---|---|
Keyboard Video and Mouse Switch STIG | 2015-12-09 |
Check Text ( C-2635r2_chk ) |
---|
The reviewer will verify the description exists and check that it accurately describes the switch and its attached ISs. An annotated drawing or diagram is acceptable. If no documentation exists, this is a finding. |
Fix Text (F-6275r1_fix) |
---|
Create a written description of the KVM switch, the ISs attached to the KVM switch, and the classification level for each IS attached to the KVM switch. |