Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000214-NDM-000157 | SRG-NET-000214-NDM-000157 | SRG-NET-000214-NDM-000157_rule | Medium |
Description |
---|
The network device user interface must provide an unspoofable and faithful communication channel between the user and any entity trusted to manipulate authorities on the user's behalf. To safeguard critical information that could be used by a malicious user to compromise the device or the entire network infrastructure, a trusted path is required for high-confidence connections between the security functions (i.e., login) of the network device and the user. |
STIG | Date |
---|---|
Network Device Management Security Requirements Guide | 2013-07-30 |
Check Text ( C-SRG-NET-000214-NDM-000157_chk ) |
---|
Verify communications between the network device and other trusted entities are configured to use secure paths to access security functions (e.g., encryption, hashing, or out-of-band subnets). If communications between the network device and other network devices is visible on the user or public network, this is a finding. |
Fix Text (F-SRG-NET-000214-NDM-000157_fix) |
---|
Configure the user interface to use a trusted communications pathway when accessing organizationally defined security functions. |