STIGQter STIGQter: STIG Summary: Cloud Computing Mission Owner Network Security Requirements Guide Version: 1 Release: 2 Benchmark Date: 30 Jan 2025:

The Mission Owner of the Infrastructure as a Service (IaaS) or Platform as a Service (PaaS) must continuously monitor and protect inbound communications from external systems, other IaaS within the same cloud service environment, or collocated mission applications for unusual or unauthorized activities or conditions.

DISA Rule

SV-259868r945592_rule

Vulnerability Number

V-259868

Group Title

SRG-NET-000390

Rule Version

SRG-NET-000390-CLD-000110

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

This applies to all Impact Levels.
FedRAMP Moderate, High.

Configure the firewall and/or IDPS for continuous monitoring of all communications inbound to the virtual IaaS or PaaS.

Configure the ACLs and security rules to detect and filter unusual or unauthorized activities or conditions such as large file transfers, persistent connections, unusual protocols and ports in use, communication with unauthorized entities, or unusually high traffic from particular segments or devices.

Check Contents

If this is a Software as a Service (SaaS), this is not applicable.

Inspect the firewall and/or intrusion detection and prevention system (IDPS) access control lists (ACLs) and filters on the firewall inbound interfaces.

Verify these rules are configured for continuous monitoring.

Verify the ACLs and security rules include rules and ACLs that detect and filter unusual or unauthorized activities or conditions such as large file transfers, persistent connections, unusual protocols and ports in use, communication with unauthorized entities, or unusually high traffic from particular segments or devices.

If the IaaS/PaaS does not continuously monitor inbound communications from external systems, other IaaS, or collocated mission applications within the same cloud service environment for unusual or unauthorized activities or conditions, this is a finding.

Vulnerability Number

V-259868

Documentable

False

Rule Version

SRG-NET-000390-CLD-000110

Severity Override Guidance

If this is a Software as a Service (SaaS), this is not applicable.

Inspect the firewall and/or intrusion detection and prevention system (IDPS) access control lists (ACLs) and filters on the firewall inbound interfaces.

Verify these rules are configured for continuous monitoring.

Verify the ACLs and security rules include rules and ACLs that detect and filter unusual or unauthorized activities or conditions such as large file transfers, persistent connections, unusual protocols and ports in use, communication with unauthorized entities, or unusually high traffic from particular segments or devices.

If the IaaS/PaaS does not continuously monitor inbound communications from external systems, other IaaS, or collocated mission applications within the same cloud service environment for unusual or unauthorized activities or conditions, this is a finding.

Check Content Reference

M

Target Key

5583