| V-285607 | CAT I · High | The Content Analysis System (CAS) must be running an operating system release that is currently supported by the vendor. | Network devices running an unsupported operating system lack current security fixes required to mitigate the risks associated with recent vulnerabilities.
Satisfies: SRG-APP-000516-NDM-000351, SRG-APP-000457-NDM-000352, SRG-APP-001035-NDM-000340 |
| V-285608 | CAT I · High | The Content Analysis System (CAS) must implement signature based and/or nonsignature-based malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code. | System entry and exit points include firewalls, remote access servers, workstations, electronic mail servers, web servers, proxy servers, notebook computers, and mobile devices. Malicious code includes viruses, worms, Trojan horses, and spyware. Malicious code can also be encoded in various formats contained within compressed or hidden files or hidden in files using techniques such as steganography. Malicious code can be inserted into systems in a variety of ways, including by electronic mail, the world wide web, and portable storage devices. Malicious code insertions occur through the exploitation of system vulnerabilities. A variety of technologies and methods exist to limit or eliminate the effects of malicious code.
Malicious code protection mechanisms include both signature- and nonsignature-based technologies. Nonsignature-based detection mechanisms include artificial intelligence techniques that use heuristics to detect, analyze, and describe the characteristics or behavior of malicious code and to provide controls against such code for which signatures do not yet exist or for which existing signatures may not be effective. Malicious code for which active signatures do not yet exist or may be ineffective includes polymorphic malicious code (i.e., code that changes signatures when it replicates). Nonsignature-based mechanisms also include reputation-based technologies. In addition to the above technologies, pervasive configuration management, comprehensive software integrity controls, and anti-exploitation software may be effective in preventing the execution of unauthorized code. Malicious code may be present in commercial off-the-shelf software as well as custom-built software and could include logic bombs, backdoors, and other types of attacks that could affect organizational mission and business functions.
In situations where malicious code cannot be detected by detection methods or technologies, organizations rely on other types of controls, including secure coding practices, configuration management and control, trusted procurement processes, and monitoring practices to ensure that software does not perform functions other than the functions intended. Organizations may determine that, in response to the detection of malicious code, different actions may be warranted. For example, organizations can define actions in response to malicious code detection during periodic scans, the detection of malicious downloads, or the detection of maliciousness when attempting to open or execute files. |
| V-285609 | CAT I · High | The Content Analysis System (CAS) must be configured to operate in a FIPS-compliant mode to ensure the use of FIPS 140-3-validated cryptographic modules and algorithms. | Unencrypted and weakly encrypted connections used for administrative sessions are highly susceptible to man-in-the-middle (MITM) attacks, eavesdropping, and session hijacking. If nonsecure protocols (such as HTTP or Telnet) or deprecated cryptographic algorithms are permitted, malicious actors can intercept sensitive management traffic, capture administrative credentials, or inject unauthorized commands into the session stream.
To mitigate these risks, DoW policy mandates that all administrative communications must be protected using strong, approved cryptography. This ensures the confidentiality of the data in transit (preventing unauthorized viewing), the integrity of the session (preventing unauthorized modification), and the authenticity of the endpoints (ensuring the administrator is communicating with the genuine device).
For the Broadcom CAS, enforcing FIPS mode ensures the appliance strictly utilizes FIPS 140-3-validated cryptographic modules. Activating this mode inherently disables nonsecure legacy protocols and weak ciphers, guaranteeing that all administrative management interfaces rely solely on DoW-approved encryption standards to protect the system from exploitation.
Satisfies: SRG-APP-000179-NDM-000265, SRG-APP-000142-NDM-000245, SRG-APP-000224-NDM-000270, SRG-APP-000411-NDM-000330, SRG-APP-000412-NDM-000331 |
| V-285611 | CAT I · High | The Content Analysis System (CAS) must enforce Role-Based Access Control (RBAC) to ensure least privilege and protect system configurations, cryptographic settings, and audit records from unauthorized access or modification. | If a network device does not strictly enforce access control policies, a compromised account or an insider threat could gain unrestricted access to the entire system. Without the principle of least privilege and separation of duties, a standard administrator might be able to alter cryptographic keys, modify security policies, or delete audit logs to cover their tracks.
To mitigate this risk, the system must employ RBAC. By mapping authenticated users to specific, restricted roles (such as separating full Administrators from Read-Only viewers), the CAS ensures that users are only granted the specific permissions necessary to perform their assigned duties. This architectural enforcement protects the integrity of audit trails, secures cryptographic modules, and ensures compliance with DoW access control mandates.
Network devices that rely on AAA brokers for authentication and authorization services may need to identify the available security groups or access levels available on the network devices and convey that information to the AAA operator. Once the AAA broker identifies the user persona on the centralized directory service, the user’s security group memberships can be retrieved. The AAA operator may need to create a mapping that links target security groups from the directory service to the appropriate security groups or access levels on the network device. Once these mappings are configured, authorizations can happen dynamically, based on each user’s directory service group membership.
Satisfies: SRG-APP-000033-NDM-000212, SRG-APP-000119-NDM-000236, SRG-APP-000120-NDM-000237, SRG-APP-000121-NDM-000238, SRG-APP-000122-NDM-000239, SRG-APP-000123-NDM-000240, SRG-APP-000133-NDM-000244, SRG-APP-000231-NDM-000271, SRG-APP-000329-NDM-000287, SRG-APP-000340-NDM-000288, SRG-APP-000378-NDM-000302, SRG-APP-000380-NDM-000304, SRG-APP-000408-NDM-000314, SRG-APP-000516-NDM-000335 |
| V-285618 | CAT I · High | The Content Analysis System (CAS) must disable nonsecure ports, protocols, and services to prevent unauthorized access and protect the integrity of the system. | Authentication for administrative (privileged level) access to the device is required at all times. An account can be created on the device's local database for use when the authentication server is down or connectivity between the device and the authentication server is not operable. This account is referred to as the account of last resort since it is intended to be used as a last resort and when immediate administrative access is absolutely necessary.
The account of last resort logon credentials must be stored in a sealed envelope and kept in a safe. The safe must be periodically audited to verify the envelope remains sealed. The signature of the auditor and the date of the audit should be added to the envelope as a record. Administrators should secure the credentials and disable the root account (if possible) when not needed for system administration functions. |
| V-285620 | CAT I · High | The Content Analysis System (CAS) must disable nonsecure TLS versions to prevent the use of deprecated cryptographic protocols for network communications. | Legacy cryptographic protocols, such as TLS version 1.0 and 1.1, contain inherent design flaws and known vulnerabilities that allow attackers to decrypt or manipulate data in transit. To secure the system's communication channels and APIs (such as the ICAP interface), these nonsecure protocols must be explicitly disabled. The appliance must be configured to enforce only DoW-approved, secure protocols (TLS 1.2 and TLS 1.3) to ensure the confidentiality and integrity of all transmitted data. |
| V-285621 | CAT I · High | The Content Analysis System (CAS) must use DoW Public Key Infrastructure (PKI) to enforce multifactor authentication for all interactive administrative logins. | Multifactor authentication (MFA) is when two or more factors are used to confirm the identity of an individual who is requesting access to digital information resources. Valid factors include something the individual knows (e.g., username and password), something the individual has (e.g., a smartcard or token), or something the individual is (e.g., a fingerprint or biometric). Legacy information system environments only use a single factor for authentication, typically a username and password combination. Although two pieces of data are used in a username and password combination, this is still considered single factor because an attacker can obtain access simply by learning what the user knows. Common attacks against single-factor authentication are attacks on user passwords. These attacks include brute force password guessing, password spraying, and password credential stuffing. MFA, along with strong user account hygiene, helps mitigate against the threat of having account passwords discovered by an attacker. Even in the event of a password compromise, with MFA implemented and required for interactive login, the attacker still needs to acquire something the user has or replicate a piece of user’s biometric digital presence.
Private industry recognizes and uses a wide variety of MFA solutions. However, DoW public key infrastructure (PKI) is the only prescribed method approved for DoW organizations to implement MFA. For authentication purposes, centralized DoW certificate authorities (CA) issue PKI certificate key pairs (public and private) to individuals using the prescribed x.509 format. The private certificates that have been generated by the issuing CA are downloaded and saved to smartcards which, within DoW, are referred to as common access cards (CAC) or personal identity verification (PIV) cards. This happens at designated DoW badge facilities. The CA maintains a record of the corresponding public keys for use with PKI-enabled environments. Privileged user smartcards, or "alternate tokens", function in the same manner, so this requirement applies to all interactive user sessions (authorized and privileged users).
Note: This requirement is used in conjunction with the use of a centralized authentication server (e.g., AAA, RADIUS, LDAP), a separate but equally important requirement. The MFA configuration of this requirement provides identification and the first phase of authentication (the challenge and validated response, thereby confirming the PKI certificate that was presented by the user). The centralized authentication server will provide the second phase of authentication (the digital presence of the PKI ID as a valid user in the requested security domain) and authorization. The centralized authentication server will map validated PKI identities to valid user accounts and determine access levels for authenticated users based on security group membership and role. In cases where the centralized authentication server is not utilized by the network device for user authorization, the network device must map the authenticated identity to the user account for PKI-based authentication.
Satisfies: SRG-APP-000149-NDM-000247, SRG-APP-000825-NDM-000180 |
| V-285631 | CAT I · High | The Content Analysis System (CAS) must be configured to use DoW-approved online certificate status protocol (OCSP) responders or certificate revocation lists (CRLs) to validate certificates used for PKI-based authentication. | Once issued by a DoW certificate authority (CA), public key infrastructure (PKI) certificates are typically valid for three years or shorter within the DoW. However, there are many reasons a certificate may become invalid before the prescribed expiration date. For example, an employee may leave or be terminated and still possess the smartcard on which the PKI certificates were stored. Another example is that a smartcard containing PKI certificates may become lost or stolen. A more serious issue could be that the CA or server which issued the PKI certificates has become compromised, thereby jeopardizing every certificate keypair that was issued by the CA. These examples of revocation use cases and many more can be researched further using internet cybersecurity resources.
PKI user certificates presented as part of the identification and authentication criteria (e.g., DoW PKI as multifactor authentication [MFA]) must be checked for validity by network devices. For example, valid PKI certificates are digitally signed by a trusted DoW CA. Additionally, valid PKI certificates are not expired, and valid certificates have not been revoked by a DoW CA.
Network devices can verify the validity of PKI certificates by checking with an authoritative CA. One method of checking the status of PKI certificates is to query databases referred to as CRLs. These are lists which are published, updated, and maintained by authoritative DoW CAs. For example, once certificates are expired or revoked, issuing CAs place the certificates on a CRL. Organizations can download these lists periodically (i.e., daily or weekly) and store them locally on the devices themselves or even onto another nearby local enclave resource. Storing them locally ensures revocation status can be checked even if internet connectivity is severed at the enclave’s point of presence (PoP). However, CRLs can be rather large in storage size and further, the use of CRLs can be rather taxing on some computing resources.
Another method of validating certificate status is to use the OCSP. Using OCSP, a requestor (i.e., the network device which the user is trying to authenticate to) sends a request to an authoritative CA challenging the validity of a certificate that has been presented for identification and authentication. The CA receives the request and sends a digitally signed response indicating the status of the user’s certificate as valid, revoked, or unknown. Network devices should only allow access for responses that indicate the certificates presented by the user were considered valid by an approved DoW CA. OCSP is the preferred method because it is fast, provides the most current status, and is lightweight. |
| V-285632 | CAT I · High | The Content Analysis System (CAS) must be configured to use a centralized authentication server to securely map PKI-authenticated identities to administrative user accounts and roles. | Without mapping the PKI certificate to a unique user account, the ability to determine the identities of individuals or the status of their nonrepudiation is considerably impacted during forensic analysis. A strength of using PKI as multifactor authentication (MFA) is that it can help ensure only the assigned individual is using their associated user account. This can only be accomplished if the network device is configured to enforce the relationship which binds PKI certificates to unique user accounts.
Local accounts (accounts created, stored, and maintained locally on the network device) should be avoided in lieu of using a centrally managed directory service. Local accounts empower the same workgroup who will be operating the network infrastructure to also control and manipulate access methods, thus creating operational autonomy. This undesirable approach breaks the concept of separation of duties. Additionally, local accounts are susceptible to poor cyber hygiene because they create another user database that must be maintained by the operator, whose primary focus is on running the network. Such examples of poor hygiene include dormant accounts that are not disabled or deleted, employees who have left the organization but whose accounts are still present, periodic password and hash rotation, password complexity shortcomings, increased exposure to insider threat, etc. For reasons such as this, local users on network devices are frequently the targets of cyber-attacks. Instead, organizations should explore examples of centrally managed account services. These examples include the implementation of AAA concepts like the use of external Remote Authentication Dial-In User Service (RADIUS) and Lightweight Directory Access Protocol (LDAP) directory service brokers.
Satisfies: SRG-APP-000177-NDM-000263, SRG-APP-000516-NDM-000336 |
| V-285634 | CAT I · High | The Content Analysis System (CAS) must terminate all network connections associated with a device management session at the end of the session, or the session must be terminated after five minutes of inactivity. | Terminating an idle session within a short time period reduces the window of opportunity for unauthorized personnel to take control of a management session enabled on the console or console port that has been left unattended. In addition, quickly terminating an idle session will also free up resources committed by the managed network element.
Terminating network connections associated with communications sessions includes, for example, de-allocating associated TCP/IP address/port pairs at the operating system level, or de-allocating networking assignments at the application level if multiple application sessions are using a single, operating system-level network connection. This does not mean that the device terminates all sessions or network access; it only ends the inactive session and releases the resources associated with that session. |
| V-285651 | CAT I · High | The Content Analysis System (CAS) must utilize a centralized authentication server via a secure, encrypted connection to authenticate all administrative users prior to granting access. | Allowing administrators to rely solely on local, device-specific accounts makes it difficult to manage identities and maintain a consistent security posture across the enterprise. In a large DoW environment, managing individual accounts on every network device is labor-intensive and prone to error, such as failing to disable an account when a member leaves the organization. Furthermore, using unencrypted protocols (like plain LDAP) to transmit administrative credentials allows for the interception of passwords via packet sniffing.
To mitigate these risks, the CAS must be configured to utilize a centralized authentication server (such as Active Directory) via Secure LDAP (LDAPS). This architecture ensures that management access is centrally governed by enterprise security policies and that all authentication traffic is cryptographically protected, satisfying DoW mandates for secure, centralized identity management.
Satisfies: SRG-APP-000516-NDM-000336, SRG-APP-000156-NDM-000250, SRG-APP-000400-NDM-000313, SRG-APP-000820-NDM-000170 |
| V-285653 | CAT I · High | The Content Analysis System (CAS) must be configured to send log data to a central log server for the purpose of forwarding alerts to the administrators and the information system security officer (ISSO). | The aggregation of log data kept on a syslog server can be used to detect attacks and trigger an alert to the appropriate security personnel. The stored log data can be used to detect weaknesses in security that enable the network IA team to find and address these weaknesses before breaches can occur. Reviewing these logs, whether before or after a security breach, are important in showing whether someone is an internal employee or an outside threat.
Satisfies: SRG-APP-000516-NDM-000350, SRG-APP-000357-NDM-000293, SRG-APP-000515-NDM-000325 |
| V-285606 | CAT II · Medium | The Content Analysis System (CAS) must automatically perform both continuous and weekly backups of its configuration settings to a secure, remote server to ensure continuity of operations. | System-level information includes default and customized settings and security attributes, including ACLs that relate to the network device configuration, as well as software required for the execution and operation of the device. Information system backup is a critical step in ensuring system integrity and availability. If the system fails and there is no backup of the system-level information, a denial of service condition is possible for all who utilize this critical network component.
This control requires the network device to support the organizational central backup process for system-level information associated with the network device. This function may be provided by the network device itself; however, the preferred best practice is a centralized backup rather than each network device performing discrete backups.
Satisfies: SRG-APP-000516-NDM-000340, SRG-APP-000516-NDM-000341 |
| V-285610 | CAT II · Medium | The Content Analysis System (CAS) must limit the number of concurrent sessions to a maximum of three for each account type. | Device management includes the ability to control the number of administrators and management sessions that manage a device. Limiting the number of allowed administrators and sessions per administrator based on account type, role, or access type is helpful in limiting risks related to denial of service (DoS) attacks.
This requirement addresses concurrent sessions for administrative accounts and does not address concurrent sessions by a single administrator via multiple administrative accounts. The maximum number of concurrent sessions should be defined based upon mission needs and the operational environment for each system. At a minimum, limits must be set for SSH, HTTPS, account of last resort, and root account sessions. |
| V-285612 | CAT II · Medium | The Content Analysis System (CAS) must be configured to enforce the limit of three consecutive invalid logon attempts, after which time it must block any login attempt for 15 minutes. | By limiting the number of failed login attempts, the risk of unauthorized system access via user password guessing, otherwise known as brute-forcing, is reduced. |
| V-285613 | CAT II · Medium | The Content Analysis System (CAS) must display the Standard Mandatory DoW Notice and Consent Banner before granting access to the device. | Display of the DoW-approved use notification before granting access to the network device ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.
System use notifications are required only for access via logon interfaces with human users.
Satisfies: SRG-APP-000068-NDM-000215, SRG-APP-000069-NDM-000216 |
| V-285614 | CAT II · Medium | The Content Analysis System (CAS) must map the authenticated identity to the user account for PKI-based authentication. | This requirement supports nonrepudiation of actions taken by an administrator and is required to maintain the integrity of the configuration management process. All configuration changes to the network device are logged, and administrators authenticate with two-factor authentication before gaining administrative access. Together, these processes will ensure the administrators can be held accountable for the configuration changes they implement.
To meet this requirement, the network device must log administrator access and activity. |
| V-285619 | CAT II · Medium | The Content Analysis System (CAS) must be configured with only one local account to be used as the account of last resort in the event the authentication server is unavailable. | Authentication for administrative (privileged level) access to the device is required at all times. An account can be created on the device's local database for use when the authentication server is down or connectivity between the device and the authentication server is not operable. This account is referred to as the account of last resort since it is intended to be used as a last resort and when immediate administrative access is absolutely necessary.
The account of last resort logon credentials must be stored in a sealed envelope and kept in a safe. The safe must be periodically audited to verify the envelope remains sealed. The signature of the auditor and the date of the audit should be added to the envelope as a record. Administrators should secure the credentials and disable the root account (if possible) when not needed for system administration functions. |
| V-285623 | CAT II · Medium | The Content Analysis System (CAS) must enforce a minimum 15-character password length. | Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks. Password length is one factor of several that helps to determine strength and how long it takes to crack a password.
The shorter the password, the lower the number of possible combinations that must be tested before the password is compromised. Use of more characters in a password helps to increase exponentially the time and/or resources required to compromise the password. |
| V-285624 | CAT II · Medium | The Content Analysis System (CAS) must enforce password complexity by requiring that at least one uppercase character be used. | Use of a complex passwords helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.
Password complexity is one factor of several that determine how long it takes to crack a password. The more complex the password is, the greater the number of possible combinations that need to be tested before the password is compromised.
Multifactor authentication (MFA) is required for all administrative and user accounts on network devices, except for an account of last resort and (where applicable) a root account. Passwords should only be used when MFA using PKI is not available, and for the account of last resort and root account. |
| V-285625 | CAT II · Medium | The Content Analysis System (CAS) must enforce password complexity by requiring that at least one lowercase character be used. | Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.
Password complexity is one factor of several that determine how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that need to be tested before the password is compromised.
Multifactor authentication (MFA) is required for all administrative and user accounts on network devices, except for an account of last resort and (where applicable) a root account. Passwords should only be used when MFA using PKI is not available, and for the account of last resort and root account. |
| V-285626 | CAT II · Medium | The Content Analysis System (CAS) must enforce password complexity by requiring that at least one numeric character be used. | Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.
Password complexity is one factor of several that determine how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that need to be tested before the password is compromised.
Multifactor authentication (MFA) is required for all administrative and user accounts on network devices, except for an account of last resort and (where applicable) a root account. Passwords should only be used when MFA using PKI is not available, and for the account of last resort and root account. |
| V-285627 | CAT II · Medium | The Content Analysis System (CAS) must enforce password complexity by requiring that at least one special character be used. | Use of a complex password helps to increase the time and resources required to compromise the password. Password complexity, or strength, is a measure of the effectiveness of a password in resisting attempts at guessing and brute-force attacks.
Password complexity is one factor of several that determine how long it takes to crack a password. The more complex the password, the greater the number of possible combinations that need to be tested before the password is compromised.
Multifactor authentication (MFA) is required for all administrative and user accounts on network devices, except for an account of last resort and (where applicable) a root account. Passwords should only be used when MFA using PKI is not available, and for the account of last resort and root account. |
| V-285628 | CAT II · Medium | The Content Analysis System (CAS) must require that when a password is changed, the characters are changed in at least eight of the positions within the password. | If the application allows the user to consecutively reuse extensive portions of passwords, this increases the chances of password compromise by increasing the window of opportunity for attempts at guessing and brute-force attacks.
The number of changed characters refers to the number of changes required with respect to the total number of positions in the current password. In other words, characters may be the same within the two passwords; however, the positions of the like characters must be different.
Multifactor authentication (MFA) is required for all administrative and user accounts on network devices, except for an account of last resort and (where applicable) a root account. Passwords should only be used when MFA using PKI is not available, and for the account of last resort and root account. |
| V-285641 | CAT II · Medium | The Content Analysis System (CAS) must provide an immediate real-time alert to appropriate personnel (such as the system administrator [SA] and information system security officer [ISSO]) upon the detection of an audit failure or the unauthorized access, modification, or deletion of audit information. | It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without a real-time alert, security personnel may be unaware of an impending failure of the audit capability and system operation may be adversely affected.
Alerts provide organizations with urgent messages. Real-time alerts provide these messages immediately (i.e., the time from event detection to alert occurs in seconds or less).
Satisfies: SRG-APP-000360-NDM-000295, SRG-APP-000795-NDM-000130 |
| V-285642 | CAT II · Medium | The Content Analysis System (CAS) must record time stamps for audit records that can be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT). | If time stamps are not consistently applied and there is no common time reference, it is difficult to perform forensic analysis.
Time stamps generated by the application include date and time. Time is commonly expressed in UTC, a modern continuation of GMT, or local time with an offset from UTC. |
| V-285644 | CAT II · Medium | The Content Analysis System (CAS) must be configured to authenticate Simple Network Management Protocol (SNMP) messages using a Federal Information Processing Standards (FIPS)-validated Keyed-Hash Message Authentication Code (HMAC). | Without authenticating devices, unidentified or unknown devices may be introduced, thereby facilitating malicious activity. Bidirectional authentication provides stronger safeguards to validate the identity of other devices for connections that are of greater risk.
A local connection is any connection with a device communicating without the use of a network. A network connection is any connection with a device that communicates through a network (e.g., local area or wide area network, internet). A remote connection is any connection with a device communicating through an external network (e.g., the internet).
Because of the challenges of applying this requirement on a large scale, organizations are encouraged to only apply the requirement to those limited number (and type) of devices that truly need to support this capability. |
| V-285645 | CAT II · Medium | The Content Analysis System (CAS) must be configured to authenticate Network Time Protocol (NTP) sources using authentication with Federal Information Processing Standards (FIPS)-compliant algorithms. | If NTP is not authenticated, an attacker can introduce a rogue NTP server. This rogue server can then be used to send incorrect time information to network devices, which will make log timestamps inaccurate and affect scheduled actions.
NTP authentication is used to prevent this tampering by authenticating the time source. |
| V-285646 | CAT II · Medium | The Content Analysis System (CAS) must enforce approved authorizations for controlling the flow of management information and protect against known types of denial-of-service (DoS) attacks by implementing a web-management access list. | DoS is a condition when a resource is not available for legitimate users. When this occurs, the organization either cannot accomplish its mission or must operate at degraded capacity.
This requirement addresses the configuration of network devices to mitigate the impact of DoS attacks that have occurred or are ongoing on device availability. For each network device, known and potential DoS attacks must be identified and solutions for each type implemented. A variety of technologies exist to limit or, in some cases, eliminate the effects of DoS attacks (e.g., limiting processes or restricting the number of sessions the device opens at one time). Employing increased capacity and bandwidth, combined with service redundancy, may reduce the susceptibility to some DoS attacks.
The security safeguards cannot be defined at the DoW level because they vary according to the capabilities of the individual network devices and the security controls applied on the adjacent networks (for example, firewalls performing packet filtering to block DoS attacks).
Satisfies: SRG-APP-000435-NDM-000315, SRG-APP-000038-NDM-000213 |
| V-285649 | CAT II · Medium | The Content Analysis System (CAS) must be configured to generate audit records and alert administrators upon detecting potential system or file integrity violations using Intelligent Connection Traffic Monitoring (ICTM) and Hash Reputation. | Without an audit capability, an integrity violation may not be detected. Organizations select response actions based on types of software, specific software, or information for which there are potential integrity violations. The integrity verification application must be configured to perform one or more of following actions: Generates an audit record; alerts current user; alerts organization-defined personnel or roles. The organization may define additional actions to be taken. |
| V-285650 | CAT II · Medium | The Content Analysis System (CAS) must generate audit records for all security-relevant events, including successful and unsuccessful logons, account management actions, privilege usage, and configuration changes. | Without comprehensive audit logging, organizations cannot establish, correlate, and investigate the events relating to a security incident or identify those responsible for unauthorized activities. If the network device fails to log critical security-relevant events—such as administrative logins, account modifications, privilege escalations, and system configuration changes—system administrators (SAs) and information system security officers (ISSOs) will lack the forensic evidence required to detect, analyze, and remediate cyber threats or insider abuses. Configuring the CAS to include all audit information ensures that a complete, DoW-compliant audit trail is generated and captured for all administrative and system-level actions.
Satisfies: SRG-APP-000516-NDM-000334, SRG-APP-000026-NDM-000208, SRG-APP-000027-NDM-000209, SRG-APP-000028-NDM-000210, SRG-APP-000029-NDM-000211, SRG-APP-000091-NDM-000223, SRG-APP-000095-NDM-000225, SRG-APP-000096-NDM-000226, SRG-APP-000097-NDM-000227, SRG-APP-000098-NDM-000228, SRG-APP-000099-NDM-000229, SRG-APP-000100-NDM-000230, SRG-APP-000101-NDM-000231, SRG-APP-000319-NDM-000283, SRG-APP-000343-NDM-000289, SRG-APP-000381-NDM-000305, SRG-APP-000495-NDM-000318, SRG-APP-000499-NDM-000319, SRG-APP-000503-NDM-000320, SRG-APP-000504-NDM-000321, SRG-APP-000505-NDM-000322, SRG-APP-000506-NDM-000323 |
| V-285652 | CAT II · Medium | The Content Analysis System (CAS) must obtain its public key certificates from an appropriate certificate policy through an approved service provider. | For user certificates, each organization obtains certificates from an approved, shared service provider, as required by OMB policy. For federal agencies operating a legacy public key infrastructure cross-certified with the Federal Bridge Certification Authority at medium assurance or higher, this Certification Authority will suffice. |
| V-285654 | CAT II · Medium | The Content Analysis System (CAS) must be configured to verify, when users create or update passwords, the passwords are not found on the list of commonly used, expected, or compromised passwords in IA-5 (1) (a) for password-based authentication. | Password-based authentication applies to passwords regardless of whether they are used in single-factor or multifactor authentication. Long passwords or passphrases are preferable over shorter passwords. Enforced composition rules provide marginal security benefits while decreasing usability. However, organizations may choose to establish certain rules for password generation (e.g., minimum character length for long passwords) under certain circumstances and can enforce this requirement in IA-5(1)(h). Account recovery can occur, for example, in situations when a password is forgotten. Cryptographically protected passwords include salted one-way cryptographic hashes of passwords. The list of commonly used, compromised, or expected passwords includes passwords obtained from previous breach corpuses, dictionary words, repetitive or sequential characters, and default manufacturer passwords. The list includes context-specific words, such as the name of the service, username, and derivatives thereof. |
| V-285655 | CAT II · Medium | The Content Analysis System (CAS) must be configured to allow user selection of long passwords and passphrases, including spaces and all printable characters for password-based authentication. | Password-based authentication applies to passwords regardless of whether they are used in single-factor or multifactor authentication. Long passwords or passphrases are preferable over shorter passwords. Enforced composition rules provide marginal security benefits while decreasing usability. However, organizations may choose to establish certain rules for password generation (e.g., minimum character length for long passwords) under certain circumstances and can enforce this requirement in IA-5(1)(h). Account recovery can occur, for example, in situations when a password is forgotten. Cryptographically protected passwords include salted one-way cryptographic hashes of passwords. The list of commonly used, compromised, or expected passwords includes passwords obtained from previous breach corpuses, dictionary words, and repetitive or sequential characters. The list includes context-specific words, such as the name of the service, username, and derivatives thereof. |
| V-285656 | CAT II · Medium | The Content Analysis System (CAS) must be configured to implement certificate revocation checking to support path discovery and validation for public key-based authentication. | Public key cryptography is a valid authentication mechanism for individuals, machines, and devices. For PKI solutions, status information for certification paths includes certificate revocation lists or certificate status protocol responses like OCSP. For PIV cards, certificate validation involves the construction and verification of a certification path to the Common Policy Root trust anchor, which includes certificate policy processing. Implementing a local cache of revocation data to support path discovery and validation also supports system availability in situations where organizations are unable to access revocation information via the network. |
| V-285657 | CAT II · Medium | The Content Analysis System (CAS) must be configured to protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by logically separated communications paths. | Nonlocal maintenance and diagnostic activities are conducted by individuals who communicate through either an external or internal network. Communications paths can be logically separated using encryption. |
| V-285658 | CAT II · Medium | The Content Analysis System (CAS) must be configured to include only approved trust anchors in trust stores or certificate stores managed by the organization. | Public key infrastructure (PKI) certificates are certificates with visibility external to organizational systems and certificates related to the internal operations of systems, such as application-specific time services. In cryptographic systems with a hierarchical structure, a trust anchor is an authoritative source (i.e., a certificate authority [CA]) for which trust is assumed and not derived. A root certificate for a PKI system is an example of a trust anchor. A trust store or certificate store maintains a list of trusted root certificates. |
| V-285659 | CAT II · Medium | The Content Analysis System (CAS) must be configured to synchronize system clocks within and between systems. | The loss of connectivity to a particular authoritative time source will result in the loss of time synchronization (free-run mode) and increasingly inaccurate time stamps on audit events and other functions.
Multiple time sources provide redundancy by including a secondary source. Time synchronization is usually a hierarchy; clients synchronize time to a local source while that source synchronizes time to a more accurate source. The network device must use an authoritative time server and/or be configured to use redundant authoritative time sources. This requirement is related to the comparison done in CCI-001891.
DoW-approved solutions consist of a combination of a primary and secondary time source using a combination or multiple instances of the following: a time server designated for the appropriate DoW network (NIPRNet/SIPRNet); United States Naval Observatory (USNO) time servers; and/or the Global Positioning System (GPS). The secondary time source must be located in a different geographic region than the primary time source.
Satisfies: SRG-APP-000920-NDM-000320, SRG-APP-000925-NDM-000330 |