STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Protected Distribution System (PDS) Monitoring - Technical Inspections

DISA Rule

SV-41021r3_rule

Vulnerability Number

V-30977

Group Title

PDS Monitoring - Technical Inspections

Rule Version

CS-06.03.01

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

Correction of this finding can only be made by complete compliance with all the following CNSSI 7003 requirements:

1. Technical inspections of PDS must be conducted at least one or more times annually IAW Table 4. PDS Technical Inspection Schedule, of the CNSSI 7003.

2. Checks and results must be documented and retained on file for a minimum of one year - or longer if required by the AO.

3. The person selected to accomplish the technical system inspection must be trained to recognize changes in the technical aspects of PDS, e.g., by-pass circuitry, attachment or removal of devices or components, inappropriate or suspicious signal levels, and mechanical, TEMPEST, and RED/BLACK integrity of the PDS. If conducted by the CTTA this meets the requirement; otherwise, sufficient documented proof of training must be provided for the person conducting the inspection.

NOTE: This check is applicable within a tactical environment in a fixed facility but not applicable in a mobile field environment.

Check Contents

Check to ensure:

1. Technical inspections of PDS are conducted at least one or more times annually IAW Table 4. PDS Technical Inspection Schedule of the CNSSI 7003.

2. Checks and results must be documented and retained on file for a minimum of one year - or longer if required by the AO.

3. The person selected to accomplish the technical system inspection is trained to recognize changes in the technical aspects of PDS, e.g., by-pass circuitry, attachment or removal of devices or components, inappropriate or suspicious signal levels, and mechanical, TEMPEST, and RED/BLACK integrity of the PDS. If conducted by the CTTA this meets the requirement; otherwise, sufficient documented proof of training must be provided for the person conducting the inspection.

NOTE: This check is applicable within a tactical environment in a fixed facility but not applicable in a mobile field environment.

Vulnerability Number

V-30977

Documentable

False

Rule Version

CS-06.03.01

Severity Override Guidance

Check to ensure:

1. Technical inspections of PDS are conducted at least one or more times annually IAW Table 4. PDS Technical Inspection Schedule of the CNSSI 7003.

2. Checks and results must be documented and retained on file for a minimum of one year - or longer if required by the AO.

3. The person selected to accomplish the technical system inspection is trained to recognize changes in the technical aspects of PDS, e.g., by-pass circuitry, attachment or removal of devices or components, inappropriate or suspicious signal levels, and mechanical, TEMPEST, and RED/BLACK integrity of the PDS. If conducted by the CTTA this meets the requirement; otherwise, sufficient documented proof of training must be provided for the person conducting the inspection.

NOTE: This check is applicable within a tactical environment in a fixed facility but not applicable in a mobile field environment.

Check Content Reference

M

Target Key

2506

Comments