STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN Gateway must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

DISA Rule

SV-279018r1138041_rule

Vulnerability Number

V-279018

Group Title

SRG-NET-000015

Rule Version

SRG-NET-000015-VPN-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN Gateway to enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

Check Contents

Determine if the VPN Gateway enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

If the VPN Gateway does not enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies, this is a finding.

Vulnerability Number

V-279018

Documentable

False

Rule Version

SRG-NET-000015-VPN-000010

Severity Override Guidance

Determine if the VPN Gateway enforces approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

If the VPN Gateway does not enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies, this is a finding.

Check Content Reference

M

Target Key

2920