SV-259880r958808_rule
V-259880
SRG-OS-000370
SRG-OS-000370-CLD-000050
CAT II
10
This applies to all Impact Levels.
FedRAMP Moderate, High.
Coordinate with the cybersecurity service provider (CSSP) during cloud architecture development to ensure required security-relevant data will be accessible via the cloud service provider/cloud service offering, third-party security service subscription, and/or native application programming interface capability.
Register the IaaS/PaaS/SaaS service/application with the DOD allowlist for both inbound and outbound traffic. Configure the DOD allowlist with the ports and protocols needed to support applications and services used in the cloud environment.
Request the cloud service Provisional Authorization (PA) and registration documentation.
Verify the IaaS/PaaS/software is registered in the service/application with the DOD DMZ/IAP allowlist for both inbound and outbound traffic when traffic will cross the IAPs.
If the system/service/application is not registered with the DOD DMZ/IAP allowlist for both inbound and outbound internet-facing traffic, this is a finding.
V-259880
False
SRG-OS-000370-CLD-000050
Request the cloud service Provisional Authorization (PA) and registration documentation.
Verify the IaaS/PaaS/software is registered in the service/application with the DOD DMZ/IAP allowlist for both inbound and outbound traffic when traffic will cross the IAPs.
If the system/service/application is not registered with the DOD DMZ/IAP allowlist for both inbound and outbound internet-facing traffic, this is a finding.
M
5584