Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000210-NDM-000153 | SRG-NET-000210-NDM-000153 | SRG-NET-000210-NDM-000153_rule | Medium |
Description |
---|
This control applies to information transmitted by the network device application. Preventing the disclosure of transmitted information requires that applications take measures to employ some form of cryptographic mechanism in order to protect the information during transmission. This is usually achieved through the use of Transport Layer Security (TLS), SSL VPN, or IPSEC tunnel. Without confidentiality controls, information traveling over commercial or internal networks could be viewed or compromised without detection. Network device management traffic and other privileged communications originating from the network device must be protected by confidentiality mechanisms while in transit (i.e., transmission encryption). |
STIG | Date |
---|---|
Network Device Management Security Requirements Guide | 2013-07-30 |
Check Text ( C-SRG-NET-000210-NDM-000153_chk ) |
---|
Open the management application. Inspect the encryption configuration. Verify encryption is automatically used for all data in transit. Verify the device is configured to negotiate a key exchange before full encryption takes place when using approved cryptographic transmission algorithms. If the system is not configured to use cryptographic mechanisms to protect information in transit, this is a finding. |
Fix Text (F-SRG-NET-000210-NDM-000153_fix) |
---|
Configure the network device to protect information in transit with cryptographic mechanisms. |