The ISEC7 SPHERE must protect the confidentiality and integrity of transmitted information during preparation for transmission and during reception using cryptographic mechanisms.
DISA Rule
SV-224772r1013830_rule
Vulnerability Number
V-224772
Group Title
SRG-APP-000439
Rule Version
ISEC-06-002030
Severity
CAT II
CCI(s)
- CCI-002418 - Protect the confidentiality and/or integrity of transmitted information.
- CCI-002420 - Maintain the confidentiality and/or integrity of information during preparation for transmission.
- CCI-002421 - Implement cryptographic mechanisms to prevent unauthorized disclosure of information and/or detect changes to information during transmission.
- CCI-002422 - Maintain the confidentiality and/or integrity of information during reception.
Weight
10
Fix Recommendation
Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Using the drop-down menu for protocols, select +TLSv1.2, +TLSv1.3.
Click "Update".
Restart the ISEC7 SPHERE Web service.
Check Contents
Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Verify protocols is set to +TLSv1.2, +TLSv1.3.
If protocols is not set to +TLSv1.2 or higher, this is a finding.
Vulnerability Number
V-224772
Documentable
False
Rule Version
ISEC-06-002030
Severity Override Guidance
Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Verify protocols is set to +TLSv1.2, +TLSv1.3.
If protocols is not set to +TLSv1.2 or higher, this is a finding.
Check Content Reference
M
Target Key
4200