Check: DSN03.03
Defense Switched Network (DSN) STIG:
DSN03.03
(in versions v2 r8 through v2 r7)
Title
Contract requirements for STIG compliance and validation must be enforced. (Cat III impact)
Discussion
The ISSO must ensure that commercially contracted systems and services supporting the DSN comply with all applicable STIGs in accordance with contract requirements. STIG compliance is DoD policy and must be accomplished to the greatest extent possible so that any information system may be Certified and Accredited, operated, and connected to other systems if applicable. Placing this requirement in procurement contracts puts the vendor on notice that their product or solution must support these DoD policy requirements. The responsibility of monitoring compliance of contract requirements falls to the AO, ISSM, ISSO, and/or SA responsible for operating the system in compliance with policy. Placing compliance requirements in a contract provides no assurance that they are being met if there is no validation or enforcement of the contract requirements.
Check Content
Review site documentation to confirm a policy and procedure enforce contract requirements for STIG compliance and validation. If a policy and procedure do not enforce contract requirements for STIG compliance and validation, this is a finding.
Fix Text
Implement site policy and procedures to enforce contract requirements for STIG compliance and validation.
Additional Identifiers
Rule ID: SV-8837r2_rule
Vulnerability ID: V-8342
Group Title: Contract STIG compliance
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |