STIGUI
V-285613CAT II — Medium severitySV-285613r1273105_rule

The Content Analysis System (CAS) must display the Standard Mandatory DoW Notice and Consent Banner before granting access to the device.

Rule version BCAS-ND-001120 · STIG v1 · 2026-09-16

Discussion

Display of the DoW-approved use notification before granting access to the network device ensures privacy and security notification verbiage used is consistent with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance.

System use notifications are required only for access via logon interfaces with human users.

Satisfies: SRG-APP-000068-NDM-000215, SRG-APP-000069-NDM-000216

Check

Verify the DoW consent banner is enabled and the required banner text is displayed with the following steps:

Validate the banner from the Web UI: 1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> Consent Banner. 3. Verify "Show Consent Banner" is checked. 4. Verify the exact required banner is displayed in the "Banner Text" field. (Note: The required text is found below. This can also be accomplished by clicking "Display current consent banner" under the preview section of this page.)

Validate the banner from SSH access: 1. Log on to the SSH CLI with an administrative account. 2. Enter "show running-config consent-banner".

Required Banner Text: You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only. By using this IS (which includes any device attached to this IS), you consent to the following conditions: -The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations. -At any time, the USG may inspect and seize data stored on this IS. -Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose. -This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy. -Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details.

If the "Show Consent Banner" option is not checked, or if the required banner text is missing or incorrect in either the Web UI or the CLI, this is a finding.

Fix

Configure the DoW consent banner to be enabled with the required banner text with the following steps:

Configure the banner for the Web UI: 1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> Consent Banner. 3. Click the "Show Consent Banner" checkbox. 4. Under the "Banner Text" field, copy and paste the required DoW banner text exactly as specified in the Check. 5. Click "Save Changes".

Configure the banner for SSH access: 1. Log on to the SSH CLI with an administrative account. 2. Enter "enable" and provide the password. 3. Enter "configure terminal". 4. Enable the CLI banner by entering "consent-banner show-banner true". 5. Copy and paste the following command string exactly as written (with no spaces before the newlines \n):

"consent-banner banner-text "You are accessing a U.S. Government (USG) Information System (IS) that is provided for USG-authorized use only.\n\nBy using this IS (which includes any device attached to this IS), you consent to the following conditions:\n-The USG routinely intercepts and monitors communications on this IS for purposes including, but not limited to, penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM), law enforcement (LE), and counterintelligence (CI) investigations.\n-At any time, the USG may inspect and seize data stored on this IS.\n-Communications using, or data stored on, this IS are not private, are subject to routine monitoring, interception, and search, and may be disclosed or used for any USG-authorized purpose.\n-This IS includes security measures (e.g., authentication and access controls) to protect USG interests--not for your personal benefit or privacy.\n-Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching or monitoring of the content of privileged communications, or work product, related to personal representation or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work product are private and confidential. See User Agreement for details.\n""

Enter "exit" to return to the config context, and then enter "exit" again to leave configuration mode.

Identifiers

Group ID
V-285613
Group title
SRG-APP-000068-NDM-000215
Rule ID
SV-285613r1273105_rule
Check ID
C-90293r1272956_chk
Fix ID
F-90198r1272957_fix