STIGQter STIGQter: STIG Summary: CA API Gateway ALG Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 28 Apr 2017:

The CA API Gateway must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-85971r1_rule

Vulnerability Number

V-71347

Group Title

SRG-NET-000132-ALG-000087

Rule Version

CAGW-GW-000290

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open the CA API Gateway - Policy Manager.

Select “Tasks" from the main menu and chose "Manage Listen Ports".

Select any port in violation and then press the "Remove" button to remove that port in accordance with organizational requirements.

Check Contents

Open the CA API Gateway - Policy Manager.

Select "Tasks" from the main menu and chose "Manage Listen Ports".

Verify on the ports necessary to meet organizational requirements are listed.

If there are ports in violation of organizational requirements, this is a finding.

Vulnerability Number

V-71347

Documentable

False

Rule Version

CAGW-GW-000290

Severity Override Guidance

Open the CA API Gateway - Policy Manager.

Select "Tasks" from the main menu and chose "Manage Listen Ports".

Verify on the ports necessary to meet organizational requirements are listed.

If there are ports in violation of organizational requirements, this is a finding.

Check Content Reference

M

Target Key

3049

Comments