UCF STIG Viewer Logo

The network device must authenticate devices before establishing network connections using bidirectional authentication between cryptography-based devices.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000151-NDM-NA SRG-NET-000151-NDM-NA SRG-NET-000151-NDM-NA_rule Medium
Description
This requirement is for device to device authentication between network device and other network devices. Without authentication, an unauthorized device may connect to the network device and intercept monitored traffic, make configuration changes, or initiate man-in-the-middle attacks. Hence, it is imperative that authentication is bidirectional (mutual authentication) using cryptography to ensure a high level of trust and authenticity. Device authentication requires unique identification and authentication that may be defined by type, by specific device, or by a combination of type and device as deemed appropriate by the organization. The devices typically use either shared known information (e.g., Media Access Control [MAC] or Transmission Control Protocol/Internet Protocol [TCP/IP] addresses) for identification or an organizational authentication solution (e.g., IEEE 802.1x and Extensible Authentication Protocol [EAP], Radius server with EAP Transport Layer Security [TLS] authentication, Kerberos) to identify and authenticate devices on local area networks. This requirement is applicable to specific devices and does not involve the management of a network device.
STIG Date
Network Device Management Security Requirements Guide 2013-07-30

Details

Check Text ( C-SRG-NET-000151-NDM-NA_chk )
This requirement is NA for network device management.
Fix Text (F-SRG-NET-000151-NDM-NA_fix)
This requirement is NA for network device management.