SV-259870r1056198_rule
V-259870
SRG-NET-000580
SRG-NET-000580-CLD-000070
CAT I
10
This applies to all Impact Levels.
FedRAMP Moderate, High.
Configure the IaaS/PaaS to use OCSP or CRLDP to ensure revoked credentials are prohibited from establishing an allowed session. This requirement applies to the use of both user and machine credentials.
This applies to all Impact Levels.
If this is a Software as a Service (SaaS) implementation, this is not a finding.
Verify that certificate path validation is implemented to ensure revoked user and/or machine credentials are prohibited from establishing a user or machine session.
If the cloud IaaS/PaaS is not configured to use OCSP or CRLDP to ensure revoked credentials are prohibited from establishing an allowed session, this is a finding.
V-259870
False
SRG-NET-000580-CLD-000070
This applies to all Impact Levels.
If this is a Software as a Service (SaaS) implementation, this is not a finding.
Verify that certificate path validation is implemented to ensure revoked user and/or machine credentials are prohibited from establishing a user or machine session.
If the cloud IaaS/PaaS is not configured to use OCSP or CRLDP to ensure revoked credentials are prohibited from establishing an allowed session, this is a finding.
M
5583