If cipher suites using pre-shared keys are used for device authentication, the ISEC7 SPHERE must have a minimum security strength of 112 bits or higher, must only be used in networks where both the client and server are government systems, must prohibit client negotiation to TLS 1.1, TLS 1.0, SSL 2.0, or SSL 3.0 and must prohibit or restrict the use of protocols that transmit unencrypted authentication information or use flawed cryptographic algorithm for transmission.
DISA Rule
SV-224776r1013841_rule
Vulnerability Number
V-224776
Group Title
SRG-APP-000585
Rule Version
ISEC-06-002620
Severity
CAT II
CCI(s)
- CCI-000382 - Configure the system to prohibit or restrict the use of organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services.
- CCI-001453 - Implement cryptographic mechanisms to protect the integrity of remote access sessions.
- CCI-001967 - Authenticate organization-defined devices and/or types of devices before establishing a local, remote, and/or network connection using bidirectional authentication that is cryptographically based.
Weight
10
Fix Recommendation
Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Using the dropdown menu for protocols, select +TLSv1.2, +TLSv1.3.
Click "Update".
Restart the ISEC7 SPHERE Web service.
Check Contents
Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Verify protocols is set to +TLSv1.2, +TLSv1.3.
If protocols is not set to +TLSv1.2 or higher, this is a finding.
Vulnerability Number
V-224776
Documentable
False
Rule Version
ISEC-06-002620
Severity Override Guidance
Log in to the ISEC7 SPHERE Console.
Navigate to Administration >> Configuration >> Apache Tomcat Settings.
Verify protocols is set to +TLSv1.2, +TLSv1.3.
If protocols is not set to +TLSv1.2 or higher, this is a finding.
Check Content Reference
M
Target Key
4200