Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000230-NDM-000169 | SRG-NET-000230-NDM-000169 | SRG-NET-000230-NDM-000169_rule | Low |
Description |
---|
This requirement addresses communications protection at the session, versus the packet level. Maintaining the authenticity of the communications session and confidence in the mutual ongoing identity of both communicating entities, the information being transmitted may be malicious or invalid. Authenticity protection includes protecting against man-in-the-middle attacks (i.e., session hijacking) and guarding against the insertion of false information into sessions. |
STIG | Date |
---|---|
Network Device Management Security Requirements Guide | 2013-07-30 |
Check Text ( C-SRG-NET-000230-NDM-000169_chk ) |
---|
Verify the application uses session authentication mechanisms (e.g., error checking, source and destination verification, and session identification). If mechanisms are not provided to protect the authenticity of communications sessions between the network device and other network devices, this is a finding. |
Fix Text (F-SRG-NET-000230-NDM-000169_fix) |
---|
Configure the network device to require session authentication mechanisms (e.g., error checking, source and destination verification, and session identification) when communicating. |