STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Network Security Requirements Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The Mission Owner's internet-facing applications must be configured to traverse the Cloud Access Point (CAP) and Virtual Datacenter Security Stack (VDSS) prior to communicating with the internet.

DISA Rule

SV-259864r945580_rule

Vulnerability Number

V-259864

Group Title

SRG-NET-000205

Rule Version

SRG-NET-000205-CLD-000090

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

This applies to all Impact Levels.
FedRAMP Moderate, High.

Configure virtual internet-facing applications to traverse the CAP and VDSS prior to communicating with the internet.

Check Contents

If this is a Software as a Service (SaaS), this is not a finding.

If Impact Level 2, but the cloud service provider (CSP) has control over the environment, this is not a finding.

Verify that virtual internet-facing applications are configured to traverse the CAP and VDSS prior to communicating with the internet.

If virtual internet-facing applications permit direct access to the CSP or the internet, this is a finding.

Vulnerability Number

V-259864

Documentable

False

Rule Version

SRG-NET-000205-CLD-000090

Severity Override Guidance

If this is a Software as a Service (SaaS), this is not a finding.

If Impact Level 2, but the cloud service provider (CSP) has control over the environment, this is not a finding.

Verify that virtual internet-facing applications are configured to traverse the CAP and VDSS prior to communicating with the internet.

If virtual internet-facing applications permit direct access to the CSP or the internet, this is a finding.

Check Content Reference

M

Target Key

5583