Check: ENTD0050
Test and Development Zone B STIG:
ENTD0050
(in versions v1 r6 through v1 r3)
Title
The organization must document impersistent connections to the test and development environment with approval by the organizations Authorizing Official. (Cat II impact)
Discussion
An impersistent connection is any temporary connection needed to another test and development environment or DoD operational network where testing is not feasible. As any unvetted connection or device will create additional risk and compromise the entire environment, it is up to the Authorizing Official for the organization to accept the risk of an impersistent connection.
Check Content
Review documentation for impersistent connections or devices to ensure the risk has been thoroughly assessed and approved by the Authorizing Official. If no documented approval is available for impersistent connections, this is a finding.
Fix Text
Create and have on file up-to-date documentation of the authorized risk approval for impersistent connections or devices.
Additional Identifiers
Rule ID: SV-51293r1_rule
Vulnerability ID: V-39435
Group Title: ENTD0050 - Impersistent connections do not have approval.
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |