STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Network Security Requirements Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The Infrastructure as a Service (IaaS)/Platform as a Service (PaaS) must be configured to maintain separation of all management and data traffic.

DISA Rule

SV-259866r945586_rule

Vulnerability Number

V-259866

Group Title

SRG-NET-000205

Rule Version

SRG-NET-000205-CLD-000100

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This applies to all Impact Levels.
FedRAMP Moderate, High.

Configure the IaaS/PaaS to maintain separation of all management and data traffic.

Check Contents

This applies to all Impact Levels.

If this is a Software as a Service (SaaS) implementation, this is not a finding.

Verify the IaaS/PaaS is configured to maintain logical separation of all management and data traffic.

If the IaaS/PaaS does not maintain separation of all management and data traffic, this is a finding.

Vulnerability Number

V-259866

Documentable

False

Rule Version

SRG-NET-000205-CLD-000100

Severity Override Guidance

This applies to all Impact Levels.

If this is a Software as a Service (SaaS) implementation, this is not a finding.

Verify the IaaS/PaaS is configured to maintain logical separation of all management and data traffic.

If the IaaS/PaaS does not maintain separation of all management and data traffic, this is a finding.

Check Content Reference

M

Target Key

5583