Check: ENTD0340
Test and Development Zone C STIG:
ENTD0340
(in versions v1 r6 through v1 r3)
Title
Organizations interconnecting test and development environments must have MOAs, MOUs, and SLAs properly documented. (Cat II impact)
Discussion
Prior to establishing a connection with another organization, a Memorandum of Understanding (MOU), Memorandum of Agreement (MOA), and/or Service Level Agreement (SLA) must be established between the two organizations. This documentation, along with diagrams of the network topology, is required to be submitted to the DAAs for approval to connect to each other. The policy must ensure that all connections to external networks conform equally.
Check Content
Verify Authorizing Official-approved MOAs, MOUs, and SLAs are up to date and included with the organization's accreditation package. If the organization does not have MOAs, MOUs, and/or SLAs with the accreditation package, this is a finding.
Fix Text
Create MOUs, MOAs, and/or SLAs with other interconnected organizations, and then gain approval from the organization’s Authorizing Official and add the documentation to the accreditation package.
Additional Identifiers
Rule ID: SV-51540r1_rule
Vulnerability ID: V-39673
Group Title: ENTD0340 - Approved contracts are not in place between interconnected organizations.
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |