Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-39627 | ENTD0160 | SV-51485r1_rule | DCSP-1 ECSC-1 | Medium |
Description |
---|
Acting as the first hop into a test and development environment, the gateway can implement proper routing and provide a first layer of defense against attacks and other unintentional compromise or spillage of sensitive information into the operational network. |
STIG | Date |
---|---|
Test and Development Zone A Security Technical Implementation Guide | 2015-12-17 |
Check Text ( C-46800r2_chk ) |
---|
Review the network diagrams and physically check to see whether the organization has a gateway implemented for the test and development environment. If the organization has not documented or implemented a gateway for the test and development environment, this is a finding. |
Fix Text (F-44639r2_fix) |
---|
Install a gateway to separate the test and development environment from the DoD operational network. Document it in the test and development network diagrams. |