STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Information Assurance - Authorizing Official (AO) and DoDIN Connection Approval Office (CAO) Approval Documentation for use of KVM and A/B switches for Sharing of Classified and Unclassified Peripheral Devices

DISA Rule

SV-41267r3_rule

Vulnerability Number

V-31126

Group Title

Information Assurance - KVM Switch (Approval Documentation)

Rule Version

IA-10.03.01

Severity

CAT III

CCI(s)

Weight

10

Fix Recommendation

1. The Enclave Authorizing Official (AO) must specifically document the approval for use of KVM and/or A/B switches in the ATO or other official documentation signed by the AO authorizing use of switches between high-side (classified/SIPRNet) and low-side (unclassified/NIPRNet) shared devices.

2. The AO must submit initial and updated documentation (as required) to the DoDIN Connection Approval Office (CAO) reflecting the use or addition of KVM or A/B devices on a user’s enclave. The documentation may be part of the Authorization and Accreditation (A&A) documentation IAW RMF procedures or otherwise as specified by the DoDIN CAO.

3. If using KVM on SIPRNet an updated SIPRNet Connection Questionnaire (SCQ) must be submitted to the Connection Approval Office reflecting the devices on the user’s enclave - when new KVM or A/B switches are added.

Check Contents

1. Check to ensure the Enclave Authorizing Official (AO) has specifically documented the approval for use of KVM and/or A/B switches in the ATO or other official documentation signed by the AO authorizing use of switches between high-side (classified/SIPRNet) and low-side (unclassified/NIPRNet) shared devices.

2. Check to ensure the AO has submitted initial and updated documentation (as required) to the DoDIN Connection Approval Office (CAO) reflecting the use or addition of KVM or A/B devices on a user’s enclave. The documentation may be part of the Authorization and Accreditation (A&A) documentation IAW RMF procedures or otherwise as specified by the DoDIN CAO.

3. Check to ensure SIPRNet enclaves also submit an updated SIPRNet Connection Questionnaire (SCQ) to the Connection Approval Office reflecting the device on the user’s enclave - when new KVM or A/B switches are added.

TACTICAL ENVIRONMENT: The check is applicable where KVM devices are in use.

Vulnerability Number

V-31126

Documentable

False

Rule Version

IA-10.03.01

Severity Override Guidance

1. Check to ensure the Enclave Authorizing Official (AO) has specifically documented the approval for use of KVM and/or A/B switches in the ATO or other official documentation signed by the AO authorizing use of switches between high-side (classified/SIPRNet) and low-side (unclassified/NIPRNet) shared devices.

2. Check to ensure the AO has submitted initial and updated documentation (as required) to the DoDIN Connection Approval Office (CAO) reflecting the use or addition of KVM or A/B devices on a user’s enclave. The documentation may be part of the Authorization and Accreditation (A&A) documentation IAW RMF procedures or otherwise as specified by the DoDIN CAO.

3. Check to ensure SIPRNet enclaves also submit an updated SIPRNet Connection Questionnaire (SCQ) to the Connection Approval Office reflecting the device on the user’s enclave - when new KVM or A/B switches are added.

TACTICAL ENVIRONMENT: The check is applicable where KVM devices are in use.

Check Content Reference

M

Target Key

2506

Comments