Check: ENTD0010
Test and Development Zone B STIG:
ENTD0010
(in versions v1 r6 through v1 r3)
Title
Network infrastructure and systems supporting the test and development environment must be documented within the organizations accreditation package. (Cat II impact)
Discussion
Up-to-date documentation is essential in assisting with the management, auditing, and security of the network infrastructure used to support the test and development environment. Network diagrams are important because they show the overall layout where devices are physically located within the network infrastructure. Diagrams also show the relationship and connectivity between devices where possible intrusive attacks could take place. Having up-to-date network diagrams will also help show what the security, traffic, and physical impact of adding a system will be on the network.
Check Content
Review the accreditation package documentation to verify the test and development environment is correctly documented within the network diagrams and site security plan. If the organization's accreditation package does not include the test and development infrastructure in the network diagrams and system security plan, this is a finding.
Fix Text
Document network infrastructure and systems supporting the test and development environment, then include it with the accreditation package.
Additional Identifiers
Rule ID: SV-51202r1_rule
Vulnerability ID: V-39344
Group Title: ENTD0010 - The test and development infrastructure is not properly documented.
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |