STIGUI
V-285657CAT II — Medium severitySV-285657r1273151_rule

The Content Analysis System (CAS) must be configured to protect nonlocal maintenance sessions by separating the maintenance session from other network sessions with the system by logically separated communications paths.

Rule version BCAS-ND-002010 · STIG v1 · 2026-09-16

Discussion

Nonlocal maintenance and diagnostic activities are conducted by individuals who communicate through either an external or internal network. Communications paths can be logically separated using encryption.

Check

Verify ICAP secure is enabled on port 11344 and HTTPS administration is enabled on port 8082 with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICAP. 3. Locate "Service" and ensure "secure" is selected and configured for port "11344". 4. Navigate to Settings >> Web Management. 5. Locate "Web Server" and ensure "Enable HTTPS Administration" is selected and configured for port "8082".

If "secure" is not selected for ICAP, if port "11344" is not configured, or if "Enable HTTPS Administration" is not selected and configured for port "8082", this is a finding.

Fix

Configure ICAP secure on port 11344 and HTTPS administration on port 8082 with the following steps:

1. Log on to the CAS Web Management Console with an administrative account. 2. Navigate to Settings >> ICAP. 3. Locate "Service", select "secure", and enter "11344" for the port value. 4. Click "Save Changes". 5. Navigate to Settings >> Web Management. 6. Locate "Web Server", select "Enable HTTPS Administration", and enter "8082" for the port value. 7. Click "Save Changes".

Identifiers

Group ID
V-285657
Group title
SRG-APP-000880-NDM-000290
Rule ID
SV-285657r1273151_rule
Check ID
C-90337r1273088_chk
Fix ID
F-90242r1273089_fix