STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 2 Release: 9 Benchmark Date: 01 Jul 2026:

COMSEC Account Management - Appointment of Responsible Person

DISA Rule

SV-245723r1138390_rule

Vulnerability Number

V-245723

Group Title

CS-01.03.01

Rule Version

CS-01.03.01

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

A person must be identified and appointed in writing to be either the COMSEC custodian or a COMSEC Hand Receipt Holder. Alternates must also be appointed in writing.

Check Contents

Check there is a current COMSEC Custodian appointment letter or verify there is a Hand Receipt Holder for COMSEC key material received from a supporting account. NOTE: Ensure that any COMSEC account, materials or equipment being inspected is used for encryption of DODIN assets. COMSEC accounts or items not used with DODIN assets should not be inspected.

Vulnerability Number

V-245723

Documentable

False

Rule Version

CS-01.03.01

Severity Override Guidance

Check there is a current COMSEC Custodian appointment letter or verify there is a Hand Receipt Holder for COMSEC key material received from a supporting account. NOTE: Ensure that any COMSEC account, materials or equipment being inspected is used for encryption of DODIN assets. COMSEC accounts or items not used with DODIN assets should not be inspected.

Check Content Reference

M

Target Key

5410