STIGQter STIGQter: STIG Summary: Network Infrastructure Policy Security Technical Implementation Guide Version: 10 Release: 7 Benchmark Date: 24 Oct 2024:

The Intrusion Detection and Prevention System (IDPS) file checksums provided by the vendor must be compared and verified with checksums computed from CD or downloaded files.

DISA Rule

SV-251345r805990_rule

Vulnerability Number

V-251345

Group Title

NET-IDPS-032

Rule Version

NET-IDPS-032

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Establish change control procedures that include file validation and integrity.

Check Contents

Interview the SA and determine the process of software and signature validation.

If file checksums provided by the vendor are not compared and verified with checksums computed from CD or downloaded files, this is a finding.

Vulnerability Number

V-251345

Documentable

False

Rule Version

NET-IDPS-032

Severity Override Guidance

Interview the SA and determine the process of software and signature validation.

If file checksums provided by the vendor are not compared and verified with checksums computed from CD or downloaded files, this is a finding.

Check Content Reference

M

Target Key

5444