STIGQter STIGQter: STIG Summary: Firewall Security Requirements Guide Version: 3 Release: 4 Benchmark Date: 01 Jul 2026:

The firewall must use organization-defined security attributes associated with organization-defined information, source, and destination objects to enforce organization-defined information flow control policies as a basis for flow control decisions.

DISA Rule

SV-278972r1137690_rule

Vulnerability Number

V-278972

Group Title

SRG-NET-000323

Rule Version

SRG-NET-000323-FW-000007

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the firewall to use organization-defined security attributes associated with organization-defined information, source, and destination objects to enforce organization-defined information flow control policies as a basis for flow control decisions.

Check Contents

Verify the firewall is configured to use organization-defined security attributes associated with organization-defined information, source, and destination objects to enforce organization-defined information flow control policies as a basis for flow control decisions.

If the firewall does not use organization-defined security attributes to enforce information flow control policies as a basis for flow control decisions, this is a finding.

Vulnerability Number

V-278972

Documentable

False

Rule Version

SRG-NET-000323-FW-000007

Severity Override Guidance

Verify the firewall is configured to use organization-defined security attributes associated with organization-defined information, source, and destination objects to enforce organization-defined information flow control policies as a basis for flow control decisions.

If the firewall does not use organization-defined security attributes to enforce information flow control policies as a basis for flow control decisions, this is a finding.

Check Content Reference

M

Target Key

2912