Check: SOL-11.1-060080
Solaris 11 SPARC STIG:
SOL-11.1-060080
(in versions v2 r9 through v1 r10)
Title
The operating system must employ cryptographic mechanisms to recognize changes to information during transmission unless otherwise protected by alternative physical measures. (Cat II impact)
Discussion
Ensuring that transmitted information is not altered during transmission requires the operating system take feasible measures to employ transmission layer security. This requirement applies to communications across internal and external networks.
Check Content
All remote sessions must be conducted via encrypted services and ports. Ask the operator to document all configured external ports and protocols. If any unencrypted connections are used, this is a finding.
Fix Text
All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.
Additional Identifiers
Rule ID: SV-219977r877040_rule
Vulnerability ID: V-219977
Group Title: SRG-OS-000424
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001128 |
The organization employs cryptographic mechanisms to recognize changes to information during transmission unless otherwise protected by alternative physical measures. |
CCI-002421 |
Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission. |
Controls
Number | Title |
---|---|
SC-8(1) |
Cryptographic or Alternate Physical Protection |