STIGUI
V-285609CAT I — High severitySV-285609r1273161_rule

The Content Analysis System (CAS) must be configured to operate in a FIPS-compliant mode to ensure the use of FIPS 140-3-validated cryptographic modules and algorithms.

Rule version BCAS-ND-000900 · STIG v1 · 2026-09-16

Discussion

Unencrypted and weakly encrypted connections used for administrative sessions are highly susceptible to man-in-the-middle (MITM) attacks, eavesdropping, and session hijacking. If nonsecure protocols (such as HTTP or Telnet) or deprecated cryptographic algorithms are permitted, malicious actors can intercept sensitive management traffic, capture administrative credentials, or inject unauthorized commands into the session stream.

To mitigate these risks, DoW policy mandates that all administrative communications must be protected using strong, approved cryptography. This ensures the confidentiality of the data in transit (preventing unauthorized viewing), the integrity of the session (preventing unauthorized modification), and the authenticity of the endpoints (ensuring the administrator is communicating with the genuine device).

For the Broadcom CAS, enforcing FIPS mode ensures the appliance strictly utilizes FIPS 140-3-validated cryptographic modules. Activating this mode inherently disables nonsecure legacy protocols and weak ciphers, guaranteeing that all administrative management interfaces rely solely on DoW-approved encryption standards to protect the system from exploitation.

Satisfies: SRG-APP-000179-NDM-000265, SRG-APP-000142-NDM-000245, SRG-APP-000224-NDM-000270, SRG-APP-000411-NDM-000330, SRG-APP-000412-NDM-000331

Check

Verify the system is in FIPS mode with the following steps:

1. Log on to the SSH CLI with an administrative account. 2. Enter "show version". 3. Review the output for the FIPS status.

If "System is in FIPS mode" is not displayed, this is a finding.

Fix

Configure the system to enable FIPS mode with the following steps:

Note: Enabling FIPS mode will perform a factory reset, erasing all existing configurations, local user accounts, and data. This should only be performed during initial deployment or a scheduled maintenance window after all configurations have been backed up.

1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Enter "fips-mode enable". 5. When prompted to confirm the factory reset and reboot, enter "yes".

The system will reboot, reset all configurations, and initialize in FIPS-compliant mode.

Identifiers

Group ID
V-285609
Group title
SRG-APP-000179-NDM-000265
Rule ID
SV-285609r1273161_rule
Check ID
C-90289r1272944_chk
Fix ID
F-90194r1273160_fix