STIGQter STIGQter: STIG Summary: Application Layer Gateway (ALG) Security Requirements Guide (SRG) Version: 1 Release: 2 Benchmark Date: 24 Jul 2015:

The ALG must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-68749r1_rule

Vulnerability Number

V-54503

Group Title

SRG-NET-000132-ALG-000087

Rule Version

SRG-NET-000132-ALG-000087

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable ports, protocols, and/or services not required for operation of the ALG application.

Check Contents

View the configuration and vendor documentation of the ALG application to find the minimum ports, protocols, and services which are required for operation of the ALG.

Compare enabled ports, protocols, and/or services with the Ports, Protocol, and Service Management (PPSM) and IAVM requirements.

If ports, protocols, and/or services are not disabled or restricted as required by the PPSM, this is a finding.

Vulnerability Number

V-54503

Documentable

False

Rule Version

SRG-NET-000132-ALG-000087

Severity Override Guidance

View the configuration and vendor documentation of the ALG application to find the minimum ports, protocols, and services which are required for operation of the ALG.

Compare enabled ports, protocols, and/or services with the Ports, Protocol, and Service Management (PPSM) and IAVM requirements.

If ports, protocols, and/or services are not disabled or restricted as required by the PPSM, this is a finding.

Check Content Reference

M

Target Key

2489

Comments