STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 2 Release: 3 Benchmark Date: 23 Apr 2021:

The TLS VPN Gateway must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during transmission.

DISA Rule

SV-207190r608988_rule

Vulnerability Number

V-207190

Group Title

SRG-NET-000062

Rule Version

SRG-NET-000062-VPN-000200

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the TLS VPN Gateway to use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data for transmission.

Check Contents

Verify the TLS VPN Gateway is configured to use TLS 1.2 or higher to protect the confidentiality of sensitive data during transmission.

If the TLS VPN Gateway does not use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during transmission, this is a finding.

Vulnerability Number

V-207190

Documentable

False

Rule Version

SRG-NET-000062-VPN-000200

Severity Override Guidance

Verify the TLS VPN Gateway is configured to use TLS 1.2 or higher to protect the confidentiality of sensitive data during transmission.

If the TLS VPN Gateway does not use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during transmission, this is a finding.

Check Content Reference

M

Target Key

2920

Comments