SV-259863r945577_rule
V-259863
SRG-NET-000205
SRG-NET-000205-CLD-000085
CAT I
10
FedRAMP Moderate, High.
For dedicated infrastructure with an ICAP/BCAP connection (Levels 4–5 and on-premise Impact Level 2), ensure the IaaS/PaaS implements a security stack that restricts traffic flow inbound and outbound between the IaaS/PaaS and the BCAP or ICAP connection.
If this is an Impact Level 2 IaaS/PaaS implementation, this requirement is not applicable.
Review the architecture for the IaaS.
Verify that for dedicated infrastructure mission Impact Levels 4–5, the IaaS implements a security stack that restricts traffic flow inbound and outbound between the IaaS/PaaS and the BCAP or ICAP connection.
For IaaS Levels 4–5, if the IaaS does not implement a security stack that restricts traffic flow inbound and outbound between the IaaS/PaaS and the BCAP or ICAP connection, this is a finding.
V-259863
False
SRG-NET-000205-CLD-000085
If this is an Impact Level 2 IaaS/PaaS implementation, this requirement is not applicable.
Review the architecture for the IaaS.
Verify that for dedicated infrastructure mission Impact Levels 4–5, the IaaS implements a security stack that restricts traffic flow inbound and outbound between the IaaS/PaaS and the BCAP or ICAP connection.
For IaaS Levels 4–5, if the IaaS does not implement a security stack that restricts traffic flow inbound and outbound between the IaaS/PaaS and the BCAP or ICAP connection, this is a finding.
M
5583