UCF STIG Viewer Logo

The operating system must prevent encrypted data from bypassing content checking mechanisms.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-OS-000012-NA SRG-OS-000012-NA SRG-OS-000012-NA_rule Medium
Description
Information flow control regulates where information is allowed to travel within an information system and between information systems (as opposed to who is allowed to access the information) and without explicit regard to subsequent accesses to the information. When data is encrypted, mechanisms designed to examine data content to detect attacks or malicious code are unable to accomplish this task unless they are capable of unencrypting the data.
STIG Date
Red Hat Enterprise Linux 6 Security Technical Implementation Guide 2013-02-05

Details

Check Text ( C-SRG-OS-000012-NA_chk )
RHEL6 cannot support this requirement without assistance from an external application, policy, or service. This requirement is NA.
Fix Text (F-SRG-OS-000012-NA_fix)
This requirement is NA. No fix is required.