STIGUI
V-285620CAT I — High severitySV-285620r1273113_rule

The Content Analysis System (CAS) must disable nonsecure TLS versions to prevent the use of deprecated cryptographic protocols for network communications.

Rule version BCAS-ND-001335 · STIG v1 · 2026-09-16

Discussion

Legacy cryptographic protocols, such as TLS version 1.0 and 1.1, contain inherent design flaws and known vulnerabilities that allow attackers to decrypt or manipulate data in transit. To secure the system's communication channels and APIs (such as the ICAP interface), these nonsecure protocols must be explicitly disabled. The appliance must be configured to enforce only DoW-approved, secure protocols (TLS 1.2 and TLS 1.3) to ensure the confidentiality and integrity of all transmitted data.

Check

Verify nonsecure TLS versions are disabled and secure TLS versions are enforced with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICAP. 3. Under "TLS Settings", verify that "TLSv1" and "TLSv1.1" are not checked. 4. Verify that "TLSv1.2" and "TLSv1.3" are checked.

If either "TLSv1" or "TLSv1.1" are checked, or if the approved secure TLS versions are not enabled, this is a finding.

Fix

Configure the CAS to disable nonsecure TLS versions and enforce secure TLS versions with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICAP. 3. Under "TLS Settings", uncheck "TLSv1" and "TLSv1.1" to disable the nonsecure protocols. 4. Check the boxes to enable "TLSv1.2" and "TLSv1.3". 5. Click "Save Settings".

Identifiers

Group ID
V-285620
Group title
SRG-APP-000142-NDM-000245
Rule ID
SV-285620r1273113_rule
Check ID
C-90300r1272977_chk
Fix ID
F-90205r1272978_fix