UCF STIG Viewer Logo

The operating system must protect non-local maintenance sessions by separating the maintenance session from other network sessions with the information system by either physically separated communications paths or logically separated communications paths.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-OS-000267-NA SRG-OS-000267-NA SRG-OS-000267-NA_rule Medium
Description
This is a requirement that maintenance needs to be done on a separate interface or encrypted channel so as to segment maintenance activity from regular usage. When performing non-local maintenance, there is a possibility of the session being monitored and replayed to gain unauthorized access into a system.
STIG Date
Red Hat Enterprise Linux 6 Security Technical Implementation Guide 2013-02-05

Details

Check Text ( C-SRG-OS-000267-NA_chk )
RHEL6 cannot support this requirement without assistance from an external application, policy, or service. This requirement is NA.
Fix Text (F-SRG-OS-000267-NA_fix)
This requirement is NA. No fix is required.