Check: DSN16.04
Defense Switched Network (DSN) STIG:
DSN16.04
(in versions v2 r8 through v2 r7)
Title
System administrators are NOT appropriately cleared. (Cat II impact)
Discussion
Requirement: The IAO will ensure that all System Administrators are appropriately cleared. In order to maintain positive control over personnel access to DSN system components, all who are provided physical and administrative access to the components must be controlled. Confirmation of those who are authorized access must be confirmed before access is given. If physical and administrative access to systems is not confirmed and controlled, this may result in unauthorized access or compromise.
Check Content
Interview the IAO or SA and confirm compliance through discussion, review of site policy, diagrams, documentation, DAA approvals, etc as applicable.
Fix Text
Obtain a System Authorization Access Request (SAAR) DD Form 2875 for each DRSN user to validate their need-to-know
Additional Identifiers
Rule ID: SV-8468r1_rule
Vulnerability ID: V-7982
Group Title: SAs are not appropriately cleared
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |