STIGQter STIGQter: STIG Summary: Riverbed NetProfiler Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

The Riverbed NetProfiler must be configured to implement cryptographic mechanisms using a FIPS 140-2/140-3 validated algorithm to protect the confidentiality and integrity of all cryptographic functions.

DISA Rule

SV-256090r1015804_rule

Vulnerability Number

V-256090

Group Title

SRG-APP-000412-NDM-000331

Rule Version

RINP-DM-000054

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Go to Administration >> Appliance Security >> Security Compliance.

Under "Operational Modes", enable "FIPS 140-2 Compatible Cryptography".

NOTE: Configuring FIPS mode is the required DOD configuration. However, the severity of this requirement can be decreased to a CAT III if the alternative manual configuration is used to configure individual protocols because this allows non-FIPS validated algorithms to be used for some functions.

Check Contents

Go to Administration >> Appliance Security >> Security Compliance.

Check under "Operational Modes".

If "FIPS 140-2 Compatible Cryptography" is not enabled, this is a finding.

Vulnerability Number

V-256090

Documentable

False

Rule Version

RINP-DM-000054

Severity Override Guidance

Go to Administration >> Appliance Security >> Security Compliance.

Check under "Operational Modes".

If "FIPS 140-2 Compatible Cryptography" is not enabled, this is a finding.

Check Content Reference

M

Target Key

5514