Connections between the DoD enclave and the Internet or other public or commercial wide area networks must require a DMZ.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-222671SRG-APP-000516APSC-DV-003350SV-222671r961863_rule2025-09-096

Description

In order to protect DoD data and systems, all remote access to DoD information systems must be mediated through a managed access control point, such as a remote access server in a DMZ.

ℹ️ Check

Interview the application representative and determine if the application is publicly accessible. If the application is publicly accessible and traffic is not being routed through a DMZ, this is a finding.

✔️ Fix

Setup a DMZ between DoD and public networks.