UCF STIG Viewer Logo

The network device must use automated mechanisms to enforce access restrictions.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000119-NDM-000077 SRG-NET-000119-NDM-000077 SRG-NET-000119-NDM-000077_rule Medium
Description
Changes to the hardware or software components of the network device can have significant effects on the overall security of the network. Therefore, the network device must be configured to use automated mechanisms to enforce access restrictions and prevent unauthorized changes or upgrades to network device hardware or software. Access restrictions may include the following controls. (i) Physical and logical access controls, workflow automation, and media libraries; (ii) Abstract layers (e.g., changes are implemented using third party interfaces rather than directly onto the network device); and (iii) Change windows (e.g., changes occur only during specified times, making unauthorized changes easy to discover).
STIG Date
Network Device Management Security Requirements Guide 2013-07-30

Details

Check Text ( C-SRG-NET-000119-NDM-000077_chk )
Verify automated mechanisms are used to enable access restrictions to the hardware and software components of the network device.

If the network device does not have automated mechanisms in place to enforce access restrictions, this is a finding.
Fix Text (F-SRG-NET-000119-NDM-000077_fix)
Configure the network device to use automated mechanisms to enforce access restrictions.