STIGQter STIGQter: STIG Summary: Virtual Private Network (VPN) Security Requirements Guide Version: 3 Release: 5 Benchmark Date: 01 Jul 2026:

The VPN Gateway must enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.

DISA Rule

SV-279019r1138044_rule

Vulnerability Number

V-279019

Group Title

SRG-NET-000018

Rule Version

SRG-NET-000018-VPN-000015

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the VPN Gateway to enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies.

Check Contents

Determine if the VPN Gateway enforces approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies..

If the VPN Gateway transmits but does not enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies, this is a finding.

Vulnerability Number

V-279019

Documentable

False

Rule Version

SRG-NET-000018-VPN-000015

Severity Override Guidance

Determine if the VPN Gateway enforces approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies..

If the VPN Gateway transmits but does not enforce approved authorizations for controlling the flow of information within the network based on organization-defined information flow control policies, this is a finding.

Check Content Reference

M

Target Key

2920