Check: DSN04.06
Defense Switched Network (DSN) STIG:
DSN04.06
(in versions v2 r8 through v2 r7)
Title
The ISSO/IAO has not established Standard Operating Procedures. (Cat III impact)
Discussion
Requirement: The IAO will establish a standard operating procedure (SOP) or other form of record that will accomplish the following: - Identify and document all users, administrators, maintainers, managers, and their associated training requirements. - Identify and document all telephone system assets - Identify and document all telephone services required - Identify and document all telephone services that are not to be allowed - Identify and document all telephone system threats. - Identify and document all audit items as required by this document.At a minimum, the ISSO/IAO should be aware of who has what level of access to the DSN switching system, as well as possible threats to the system based on its environment. By establishing an SOP that identifies and documents all assets, services, threats, as well as users, administrators, managers and their associated operational requirements in supporting DSN systems, the ISSO/IAO will ensure that the DSN is providing the proper service securely.
Check Content
Interview the IAO or SA and confirm compliance through discussion, review of site policy, diagrams, documentation, DAA approvals, etc as applicable.
Fix Text
The ISSO/IAO should develop an SOP that will satisfy the requirements as outlined in the DSN STIG.
Additional Identifiers
Rule ID: SV-8421r1_rule
Vulnerability ID: V-7935
Group Title: The ISSO/IAO has not established SOPs
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |