STIGQter STIGQter: STIG Summary: F5 BIG-IP TMOS ALG Security Technical Implementation Guide Version: 1 Release: 3 Benchmark Date: 01 Jul 2026:

The F5 BIG-IP appliance providing user access control intermediary services must enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies.

DISA Rule

SV-266143r1137544_rule

Vulnerability Number

V-266143

Group Title

SRG-NET-000015-ALG-000016

Rule Version

F5BI-AP-300012

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

For each APM Access Policy, ensure that for each resource, all Advanced Resource Assign agents used in the configuration are explicitly configured to use an authorization list.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Click on any items that use the Advanced Resource Assign VPE object.
6. For each entry with an expression that is "Empty", click "change".
7. Add an appropriate expression that validates the user's authorization to access the resource specified in the item.
8. Click "Finished".
9. Click "Save".
10. Click "Apply Access Policy".

Check Contents

If the BIG-IP appliance does not provide user access control intermediary services, this is not applicable.

If Advanced Resource Assign VPE agent is not used in any policy, this is not a finding.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Review each Resource.
- If the Advanced Resource Assign agent is used, verify that each expression listed is explicitly configured to use an authorization list.

If the Big IP F5 appliance Access Policy has any assigned resources that are not configured with a specific authorization list, this is a finding.

Vulnerability Number

V-266143

Documentable

False

Rule Version

F5BI-AP-300012

Severity Override Guidance

If the BIG-IP appliance does not provide user access control intermediary services, this is not applicable.

If Advanced Resource Assign VPE agent is not used in any policy, this is not a finding.

From the BIG-IP GUI:
1. Access.
2. Profiles/Policies.
3. Access Profiles.
4. Click "Edit" under "Per-Session Policy" for the Access Profile.
5. Review each Resource.
- If the Advanced Resource Assign agent is used, verify that each expression listed is explicitly configured to use an authorization list.

If the Big IP F5 appliance Access Policy has any assigned resources that are not configured with a specific authorization list, this is a finding.

Check Content Reference

M

Target Key

5640