Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-30977 | CS-06.03.01 | SV-41021r2_rule | DCSR-3 ECCT-2 PESS-1 | Low |
Description |
---|
A PDS that is not inspected, monitored and maintained as required could result in undetected access, sabotage or tampering of the unencrypted transmission lines. This could directly lead to the loss or compromise of classified. |
STIG | Date |
---|---|
Traditional Security | 2013-07-11 |
Check Text ( C-39640r3_chk ) |
---|
Check to ensure: 1. Technical inspections of PDS are conducted at least one or more times annually IAW Table B-3, of the NSTISSI 7003. 2. Checks and results must be documented and retained on file for a minimum of 1-year - or longer if required by the DAA. 3. The person selected to accomplish the technical system inspection is trained to recognize changes in the technical aspects of PDS, e.g., by-pass circuitry, attachment or removal of devices or components, inappropriate or suspicious signal levels, and mechanical, TEMPEST. and RED/BLACK integrity of the PDS. If conducted by the CTTA this meets the requirement; otherwise, sufficient documented proof of training must be provided for the person conducting the inspection. Note: This check is applicable within a tactical environment in a fixed facility but not applicable in a mobile field environment. |
Fix Text (F-34788r3_fix) |
---|
Correction of this finding can only be made by complete compliance with all the following NSTISSI 7003 requirements: 1. Technical inspections of PDS must be conducted at least one or more times annually IAW Table B-3, of the NSTISSI 7003. 2. Checks and results must be documented and retained on file for a minimum of 1-year, or longer if required by the DAA. 3. The person selected to accomplish the technical system inspection must be trained to recognize changes in the technical aspects of PDS, e.g., by-pass circuitry, attachment or removal of devices or components, inappropriate or suspicious signal levels, and mechanical, TEMPEST. and RED/BLACK integrity of the PDS. If conducted by the CTTA this meets the requirement; otherwise, sufficient documented proof of training must be provided for the person conducting the inspection. Note: This check is applicable within a tactical environment in a fixed facility but not applicable in a mobile field environment. |