Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-31632 | NET0180 | SV-41919r3_rule | Medium |
Description |
---|
If network address space is not properly configured, managed, and controlled, the network could be accessed by unauthorized personnel resulting in security compromise of site information and resources. Allowing subscribers onto the network whose IP addresses are not registered with the .Mil NIC may allow unauthorized users access into the network. These unauthorized users could then monitor the network, steal passwords, and access classified information. |
STIG | Date |
---|---|
Network Infrastructure Policy Security Technical Implementation Guide | 2019-12-10 |
Check Text ( C-40348r4_chk ) |
---|
Validate global IP addresses in use on unclassified or classified networks registered through the DoD Network Information Center. For NIPRNet, go to the website https://www.nic.mil. For SIPRNet, go to the web portal at http://www.ssc.smil.mil. To verify Department of the Navy IP addresses, go to http://infosec.navy.mil.ipaddress.com. If the site is using an address space that has not been registered and allocated to the site, this is a finding. |
Fix Text (F-35552r4_fix) |
---|
Submit any unregistered and/or unauthorized global IP addresses to the DoD Network Information Center (NIC) for registration. |