Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000178-NDM-000137 | SRG-NET-000178-NDM-000137 | SRG-NET-000178-NDM-000137_rule | Medium |
Description |
---|
In the event the remote node has abnormally terminated or an upstream link from the managed device is down, the management session will be terminated. Thereby, freeing device resources and eliminating any possibility of an unauthorized user being orphaned to an open idle session of the managed device. |
STIG | Date |
---|---|
Network Device Management Security Requirements Guide | 2013-07-30 |
Check Text ( C-SRG-NET-000178-NDM-000137_chk ) |
---|
Verify sessions are terminated after an organizationally defined time period of inactivity or when session is terminated for packets identified as non-local maintenance. If the network device does not terminate all sessions when non-local maintenance is completed, this is a finding. |
Fix Text (F-SRG-NET-000178-NDM-000137_fix) |
---|
Configure the network device to terminate all sessions when non-local maintenance is completed. |