Check: DSN09.05
Defense Switched Network (DSN) STIG:
DSN09.05
(in versions v2 r8 through v2 r7)
Title
Links within the SS7 network are not encrypted. (Cat II impact)
Discussion
Requirement: The IAO will ensure that all SS7 links leaving a base/post/camp/station are encrypted. The examination of traffic patterns and statistics can reveal compromising information. Such information may include call source, destination, duration, frequency, and precedence level. The DSN common channel signaling links contain this type of information and must be protected.
Check Content
Interview the IAO or SA and confirm compliance through discussion, review of site policy, diagrams, documentation, DAA approvals, etc as applicable.
Fix Text
Ensure all SS7 links are, at a minimum, bulk encrypted before leaving the facility or installation.
Additional Identifiers
Rule ID: SV-8436r1_rule
Vulnerability ID: V-7950
Group Title: Links within the SS7 network are not encrypted.
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |