The Edge SWG must be configured to use FIPS mode.
DISA Rule
SV-279248r1170510_rule
Vulnerability Number
V-279248
Group Title
SRG-APP-000142-NDM-000245
Rule Version
SYME-ND-000100
Severity
CAT I
CCI(s)
- CCI-000382 - Configure the system to prohibit or restrict the use of organization-defined prohibited or restricted functions, system ports, protocols, software, and/or services.
- CCI-000803 - Implement mechanisms for authentication to a cryptographic module that meet the requirements of applicable laws, Executive Orders, directives, policies, regulations, standards, and guidance for such authentication.
- CCI-001188 - Generate a unique session identifier for each session with organization-defined randomness requirements.
- CCI-002890 - Implement organization-defined cryptographic mechanisms to protect the integrity of nonlocal maintenance and diagnostic communications.
- CCI-003123 - Implement organization-defined cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
Weight
10
Fix Recommendation
Note: This will wipe all configurations, so it is imperative to do this configuration before any other.
1. Log in to the Edge SWG SSH CLI.
2. Enter "fips-mode enable".
Note: This will disable all disallowed ports and protocols for management like SNMPv2c/1 and HTTP.
3. Once warnings are accepted, the system will reboot.
Check Contents
1. Log in to the Edge SWG SSH CLI.
2. Enter "show configuration".
If "FIPS mode" is not shown next to "!- Version: SGOS 7.4.x.x SWG Edition" this is a finding.
Vulnerability Number
V-279248
Documentable
False
Rule Version
SYME-ND-000100
Severity Override Guidance
1. Log in to the Edge SWG SSH CLI.
2. Enter "show configuration".
If "FIPS mode" is not shown next to "!- Version: SGOS 7.4.x.x SWG Edition" this is a finding.
Check Content Reference
M
Target Key
5726