ONTAP must be configured to implement cryptographic mechanisms using FIPS 140-2.
DISA Rule
SV-246958r961557_rule
Vulnerability Number
V-246958
Group Title
SRG-APP-000412-NDM-000331
Rule Version
NAOT-MA-000002
Severity
CAT I
CCI(s)
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-003123 - Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
- CCI-002890 - Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
Weight
10
Fix Recommendation
Configure ONTAP to use cryptographic mechanisms with "set -privilege advanced" reply "y" to continue and "security config modify -is-fips-enabled true -interface SSL".
Check Contents
Use "set -privilege advanced" reply "y" to continue and "security config show" to see if cluster FIPS mode is true.
If ONTAP is not configured to implement cryptographic mechanisms using FIPS 140-2, this is a finding.
Vulnerability Number
V-246958
Documentable
False
Rule Version
NAOT-MA-000002
Severity Override Guidance
Use "set -privilege advanced" reply "y" to continue and "security config show" to see if cluster FIPS mode is true.
If ONTAP is not configured to implement cryptographic mechanisms using FIPS 140-2, this is a finding.
Check Content Reference
M
Target Key
5415