STIGQter STIGQter: STIG Summary: Network WLAN Controller Management Security Technical Implementation Guide Version: 7 Release: 2 Benchmark Date: 25 Oct 2023:

The network device must be configured to implement cryptographic mechanisms using a FIPS 140-2 approved algorithm to protect the confidentiality of remote maintenance sessions.

DISA Rule

SV-243195r879785_rule

Vulnerability Number

V-243195

Group Title

SRG-APP-000412-NDM-000331

Rule Version

WLAN-ND-000800

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure the network device to use secure protocols with FIPS 140-2 validated cryptographic modules.

Check Contents

Review the network device configuration to verify only secure protocols using FIPS 140-2 validated cryptographic modules are used for any administrative access. Some of the secure protocols used for administrative and management access are listed below. This list is not all inclusive and represents a sample selection of secure protocols.

- SSHv2
- SCP
- HTTPS using TLS

If management connections are established using protocols without FIPS 140-2 validated cryptographic modules, this is a finding.

Vulnerability Number

V-243195

Documentable

False

Rule Version

WLAN-ND-000800

Severity Override Guidance

Review the network device configuration to verify only secure protocols using FIPS 140-2 validated cryptographic modules are used for any administrative access. Some of the secure protocols used for administrative and management access are listed below. This list is not all inclusive and represents a sample selection of secure protocols.

- SSHv2
- SCP
- HTTPS using TLS

If management connections are established using protocols without FIPS 140-2 validated cryptographic modules, this is a finding.

Check Content Reference

M

Target Key

5394