Check: SRG-NET-000344-ALG-000098
Application Layer Gateway (ALG) SRG (SRG):
SRG-NET-000344-ALG-000098
(in version v1 r2)
Title
The ALG must prohibit the use of cached authenticators after an organization-defined time period. (Cat II impact)
Discussion
If the cached authenticator information is out of date, the validity of the authentication information may be questionable. This requirement applies to all ALGs which may cache user authenticators for use throughout a session. This requirement also applies to ALGs that provide user authentication intermediary services (e.g., authentication gateway or TLS gateway). This does not apply to authentication for the purpose of configuring the device itself (device management).
Check Content
Verify the ALG prohibits the use of cached authenticators after an organization-defined time period. If the ALG does not prohibit the use of cached authenticators after an organization-defined time period, this is a finding.
Fix Text
Configure the ALG to prohibit the use of cached authenticators after an organization-defined time period.
Additional Identifiers
Rule ID: SV-68773r1_rule
Vulnerability ID: V-54527
Group Title: SRG-NET-000344-ALG-000098
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-002007 |
The information system prohibits the use of cached authenticators after an organization-defined time period. |
Controls
Number | Title |
---|---|
IA-5 (13) |
Expiration Of Cached Authenticators |