STIGQter STIGQter: STIG Summary:

Application Layer Gateway Security Requirements Guide

Version: 2

Release: 4 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-204909r1137544_ruleThe ALG must enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies.
SV-204910r1137545_ruleThe ALG must enforce approved authorizations for controlling the flow of information within the network based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.
SV-204911r1137546_ruleThe ALG must restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.
SV-204912r1137547_ruleThe ALG must immediately use updates made to policy enforcement mechanisms such as policy filters, rules, signatures, and analysis algorithms for gateway and/or intermediary functions.
SV-204913r1137548_ruleThe ALG that is part of a CDS must apply information flow control to data transferred between security domains by means of a policy filter which consists of a set of hardware and/or software.
SV-204914r987724_ruleThe ALG that is part of a CDS must allow privileged administrators to enable/disable all security policy filters used to enforce information flow control.
SV-204915r987725_ruleThe ALG that is part of a CDS must allow privileged administrators to configure and make changes to all security policy filters that are used to enforce information flow control.
SV-204916r1137549_ruleThe ALG that is part of a CDS must enforce dynamic traffic flow control based on organization-defined policies.
SV-204917r987728_ruleThe ALG that is part of a CDS must enforce organization-defined one-way information flows using hardware mechanisms.
SV-204918r1137550_ruleThe ALG that is part of a CDS must enforce information flow control using organization-defined security policy filters as a basis for flow control decisions for organization-defined information flows.
SV-204919r1173942_ruleThe ALG providing user access control intermediary services must display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to the network.
SV-204920r1173943_ruleThe ALG providing user access control intermediary services must retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
SV-204921r1173944_ruleThe ALG providing user access control intermediary services for publicly accessible applications must display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to the system.
SV-204922r395901_ruleThe ALG providing user access control intermediary services must limit the number of concurrent sessions to an organization-defined number for all accounts and/or account types.
SV-204923r395904_ruleThe ALG providing intermediary services for remote access communications traffic must ensure inbound and outbound traffic is monitored for compliance with remote access security policies.
SV-204924r395907_ruleThe ALG providing intermediary services for remote access communications traffic must use encryption services that implement NIST FIPS-validated cryptography to protect the confidentiality of remote access sessions.
SV-204925r395910_ruleThe ALG that stores secret or private keys must use FIPS-approved key management technology and processes in the production and control of private/secret cryptographic keys.
SV-204926r395913_ruleThe ALG that provides intermediary services for TLS must be configured to comply with the required TLS settings in NIST SP 800-52.
SV-204927r395916_ruleThe ALG providing intermediary services for remote access communications traffic must use NIST FIPS-validated cryptography to protect the integrity of remote access sessions.
SV-204928r395919_ruleThe ALG must produce audit records containing information to establish what type of events occurred.
SV-204929r395922_ruleThe ALG must produce audit records containing information to establish when (date and time) the events occurred.
SV-204930r395925_ruleThe ALG must produce audit records containing information to establish where the events occurred.
SV-204931r395928_ruleThe ALG must produce audit records containing information to establish the source of the events.
SV-204932r395931_ruleThe ALG must produce audit records containing information to establish the outcome of the events.
SV-204933r395934_ruleThe ALG must generate audit records containing information to establish the identity of any individual or process associated with the event.
SV-204934r1138549_ruleThe ALG must send an alert to, at a minimum, the information system security officer (ISSO) and system administrator (SA) when an audit processing failure occurs.
SV-204936r395943_ruleThe ALG must protect audit information from unauthorized read access.
SV-204937r395946_ruleThe ALG must protect audit information from unauthorized modification.
SV-204938r395949_ruleThe ALG must protect audit information from unauthorized deletion.
SV-204939r395952_ruleThe ALG must protect audit tools from unauthorized access.
SV-204940r395955_ruleThe ALG must protect audit tools from unauthorized modification.
SV-204941r395958_ruleThe ALG must protect audit tools from unauthorized deletion.
SV-204942r395961_ruleThe ALG must not have unnecessary services and functions enabled.
SV-204943r395964_ruleThe ALG must be configured to remove or disable unrelated or unneeded application proxy services.
SV-204944r395967_ruleThe ALG must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.
SV-204945r395970_ruleThe ALG providing user authentication intermediary services must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-204946r395973_ruleThe ALG providing user access control intermediary services must be configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or AAA server) which validate user account access authorizations and privileges.
SV-204947r395976_ruleThe ALG providing user authentication intermediary services must restrict user authentication traffic to specific authentication server(s).
SV-204948r954210_ruleThe ALG providing user authentication intermediary services must use multifactor authentication for network access to non-privileged accounts.
SV-204949r981631_ruleThe ALG providing user authentication intermediary services must implement replay-resistant authentication mechanisms for network access to nonprivileged accounts.
SV-204950r395985_ruleThe ALG that provides intermediary services for TLS must validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation.
SV-204951r395988_ruleThe ALG providing PKI-based user authentication intermediary services must map authenticated identities to the user account.
SV-204952r395991_ruleThe ALG providing user authentication intermediary services must uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users).
SV-204953r395994_ruleThe ALG providing content filtering must block outbound traffic containing known and unknown DoS attacks to protect against the use of internal information systems to launch any Denial of Service (DoS) attacks against other networks or endpoints.
SV-204954r1137551_ruleThe ALG must deny network communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception).
SV-204955r971530_ruleThe ALG must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after 10 minutes of inactivity; and for user sessions (non-privileged session), the session must be terminated after 15 minutes of inactivity.
SV-204956r396003_ruleThe ALG must detect, at a minimum, mobile code that is unsigned or exhibiting unusual behavior, has not undergone a risk assessment, or is prohibited for use based on a risk assessment.
SV-204957r396006_ruleThe ALG must protect the authenticity of communications sessions.
SV-204958r396009_ruleThe ALG must invalidate session identifiers upon user logout or other session termination.
SV-204959r396012_ruleThe ALG must recognize only system-generated session identifiers.
SV-204960r396015_ruleThe ALG must generate unique session identifiers using a FIPS 140-2 approved random number generator.
SV-204961r396018_ruleThe ALG must fail to a secure state upon failure of initialization, shutdown, or abort actions.
SV-204962r396021_ruleIn the event of a system failure of the ALG function, the ALG must save diagnostic information, log system messages, and load the most current security policies, rules, and signatures when restarted.
SV-204963r981632_ruleThe ALG providing content filtering must update malicious code protection mechanisms and signature definitions whenever new releases are available in accordance with organizational configuration management policy.
SV-204964r981633_ruleThe ALG providing content filtering must be configured to perform real-time scans of files from external sources at network entry/exit points as they are downloaded and prior to being opened or executed.
SV-204965r396030_ruleThe ALG providing content filtering must block malicious code upon detection.
SV-204966r396033_ruleThe ALG providing content filtering must delete or quarantine malicious code in response to malicious code detection.
SV-204967r396036_ruleThe ALG providing content filtering must send an immediate (within seconds) alert to the system administrator, at a minimum, in response to malicious code detection.
SV-204968r981634_ruleThe ALG providing content filtering must update malicious code protection mechanisms and signature definitions whenever new releases are available in accordance with organizational configuration management procedures.
SV-204969r396042_ruleThe ALG must generate error messages that provide the information necessary for corrective actions without revealing information that could be exploited by adversaries.
SV-204970r1137552_ruleThe ALG that is part of a CDS must enforce information flow control based on organization-defined metadata.
SV-204971r1137553_ruleThe ALG that is part of a CDS must block the transfer of data with malformed security attribute metadata structures.
SV-204972r987742_ruleThe ALG that is part of a CDS must decompose information into organization-defined, policy-relevant subcomponents for submission to policy enforcement mechanisms before transferring information between different security domains.
SV-204973r987743_ruleThe ALG that is part of a CDS, when transferring information between different security domains, must implement organization-defined security policy filters requiring fully enumerated formats that restrict data structure and content.
SV-204974r987744_ruleThe ALG that is part of a CDS, when transferring information between different security domains, must examine the information for the presence of organization-defined unsanctioned information.
SV-204975r987745_ruleThe ALG that is part of a CDS must prohibit the transfer of unsanctioned information in accordance with the security policy when transferring information between different security domains.
SV-204976r396063_ruleThe ALG providing content filtering must block or restrict detected prohibited mobile code.
SV-204977r396066_ruleThe ALG providing content filtering must prevent the download of prohibited mobile code.
SV-204978r831355_ruleThe ALG providing intermediary services for remote access communications traffic must control remote access methods.
SV-204979r831356_ruleThe ALG providing intermediary services for remote access communications traffic must provide the capability to immediately disconnect or disable remote access to the information system.
SV-204980r831357_ruleTo protect against data mining, the ALG providing content filtering must prevent code injection attacks from being launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
SV-204981r831358_ruleTo protect against data mining, the ALG providing content filtering must prevent code injection attacks launched against application objects including, at a minimum, application URLs and application code.
SV-204982r831359_ruleTo protect against data mining, the ALG providing content filtering must prevent SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
SV-204983r831360_ruleTo protect against data mining, the ALG providing content filtering must detect code injection attacks from being launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
SV-204984r831361_ruleTo protect against data mining, the ALG providing content filtering must detect SQL injection attacks launched against data storage objects, including, at a minimum, databases, database records, and database fields.
SV-204985r831362_ruleTo protect against data mining, the ALG providing content filtering as part of its intermediary services must detect code injection attacks launched against application objects including, at a minimum, application URLs and application code.
SV-204986r1137554_ruleThe ALG that is part of a CDS must use source and destination security attributes associated with organization-defined information, source, and/or destination objects to enforce organization-defined information flow control policies as a basis for flow control decisions.
SV-204987r1117211_ruleThe ALG that is part of a CDS, when transferring information between different security domains, must use organization-defined data type identifiers to validate data essential for information flow decisions.
SV-204988r1137555_ruleThe ALG that is part of a CDS must uniquely identify and authenticate source by organization, system, application, and/or individual for information transfer.
SV-204989r1137556_ruleThe ALG that is part of a CDS must uniquely identify and authenticate destination by organization, system, application, and/or individual for information transfer.
SV-204991r1137557_ruleThe ALG that is part of a CDS, when transferring information between different security domains, must apply the same security policy filtering to metadata as it applies to data payloads.
SV-204992r987757_ruleThe ALG that is part of a CDS must enforce the use of human reviews for organization-defined information flows under organization-defined conditions.
SV-204993r1015266_ruleThe ALG providing user access control intermediary services must provide the capability for authorized users to select a user session to capture or view.
SV-204995r831372_ruleThe ALG must off-load audit records onto a centralized log server.
SV-204996r831373_ruleThe ALG must provide an immediate real-time alert to, at a minimum, the SCA and ISSO, of all audit failure events where the detection and/or prevention function is unable to write events to either local storage or the centralized server.
SV-204997r1050784_ruleThe ALG providing user authentication intermediary services must require users to reauthenticate when organization-defined circumstances or situations require reauthentication.
SV-204998r981642_ruleThe ALG providing user authentication intermediary services must implement multifactor authentication for remote access to nonprivileged accounts such that one of the factors is provided by a device separate from the system gaining access.
SV-204999r981643_ruleThe ALG providing user authentication intermediary services must implement multifactor authentication for remote access to privileged accounts such that one of the factors is provided by a device separate from the system gaining access.
SV-205000r831377_ruleThe ALG must prohibit the use of cached authenticators after an organization-defined time period.
SV-205001r981644_ruleThe ALG providing user authentication intermediary services using PKI-based user authentication must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.
SV-205002r981646_ruleThe ALG providing user authentication intermediary services must conform to Federal Identity, Credential, and Access Management (FICAM)-issued profiles.
SV-205003r831380_ruleThe ALG providing user authentication intermediary services using PKI-based user authentication must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of protected sessions.
SV-205004r831381_ruleThe ALG providing content filtering must protect against known and unknown types of Denial of Service (DoS) attacks by employing rate-based attack prevention behavior analysis.
SV-205005r831382_ruleThe ALG must implement load balancing to limit the effects of known and unknown types of Denial of Service (DoS) attacks.
SV-205006r831383_ruleThe ALG providing content filtering must protect against known types of Denial of Service (DoS) attacks by employing signatures.
SV-205007r831384_ruleThe ALG providing content filtering must protect against or limit the effects of known and unknown types of Denial of Service (DoS) attacks by employing pattern recognition pre-processors.
SV-205008r831385_ruleThe ALG must only allow incoming communications from organization-defined authorized sources routed to organization-defined authorized destinations.
SV-205009r1138084_ruleThe ALG must fail securely in the event of an operational failure.
SV-205010r831386_ruleThe ALG must identify and log internal users associated with denied outgoing communications traffic posing a threat to external information systems.
SV-205011r831387_ruleThe ALG must behave in a predictable and documented manner that reflects organizational and system objectives when invalid inputs are received.
SV-205012r831388_ruleThe ALG providing content filtering must be configured to integrate with a system-wide intrusion detection system.
SV-205013r831389_ruleThe ALG providing content filtering must detect use of network services that have not been authorized or approved by the ISSM and ISSO, at a minimum.
SV-205014r831390_ruleThe ALG providing content filtering must generate a log record when unauthorized network services are detected.
SV-205015r831391_ruleThe ALG providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when unauthorized network services are detected.
SV-205016r831392_ruleThe ALG providing content filtering must continuously monitor inbound communications traffic crossing internal security boundaries for unusual or unauthorized activities or conditions.
SV-205017r831393_ruleThe ALG providing content filtering must continuously monitor outbound communications traffic crossing internal security boundaries for unusual/unauthorized activities or conditions.
SV-205018r971533_ruleThe ALG providing content filtering must send an alert to, at a minimum, the ISSO and ISSM when detection events occur.
SV-205019r971533_ruleThe ALG providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected.
SV-205020r971533_ruleThe ALG providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when root level intrusion events which provide unauthorized privileged access are detected.
SV-205021r971533_ruleThe ALG providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when user level intrusions which provide non-privileged access are detected.
SV-205022r971533_ruleThe ALG providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when denial of service incidents are detected.
SV-205023r971533_ruleThe ALG providing content filtering must generate an alert to, at a minimum, the ISSO and ISSM when new active propagation of malware infecting DoD systems or malicious code adversely affecting the operations and/or security of DoD systems is detected.
SV-205024r396447_ruleThe ALG that implements spam protection mechanisms must be updated automatically.
SV-205026r1207647_ruleThe ALG providing user authentication intermediary services must transmit only encrypted representations of passwords.
SV-205027r396456_ruleThe ALG must check the validity of all data inputs except those specifically identified by the organization.
SV-205028r396459_ruleThe ALG must reveal error messages only to the ISSO, ISSM, and SCA.
SV-205029r396462_ruleThe ALG must generate audit records when successful/unsuccessful attempts to access security objects occur.
SV-205030r396465_ruleThe ALG that is part of a CDS must generate audit records when successful/unsuccessful attempts to access security levels occur.
SV-205031r396468_ruleThe ALG must generate audit records when successful/unsuccessful attempts to access categories of information (e.g., classification levels) occur.
SV-205032r396471_ruleThe ALG providing user access control intermediary services must generate audit records when successful/unsuccessful attempts to modify privileges occur.
SV-205033r396474_ruleThe ALG must generate audit records when successful/unsuccessful attempts to modify security objects occur.
SV-205034r396477_ruleThe ALG must generate audit records when successful/unsuccessful attempts to modify security levels occur.
SV-205035r396480_ruleThe ALG must generate audit records when successful/unsuccessful attempts to modify categories of information (e.g., classification levels) occur.
SV-205036r396483_ruleThe ALG providing user access control intermediary services must generate audit records when successful/unsuccessful attempts to delete privileges occur.
SV-205037r396486_ruleThe ALG must generate audit records when successful/unsuccessful attempts to delete security levels occur.
SV-205038r396489_ruleThe ALG must generate audit records when successful/unsuccessful attempts to delete security objects occur.
SV-205039r396492_ruleThe ALG must generate audit records when successful/unsuccessful attempts to delete categories of information (e.g., classification levels) occur.
SV-205040r396495_ruleThe ALG providing user access control intermediary services must generate audit records when successful/unsuccessful logon attempts occur.
SV-205041r396498_ruleThe ALG providing user access control intermediary services must generate audit records showing starting and ending time for user access to the system.
SV-205042r1137559_ruleThe ALG providing encryption intermediary services must implement NIST FIPS-validated cryptography to generate cryptographic hashes.
SV-205043r1137560_ruleThe ALG providing encryption intermediary services must implement NIST FIPS-validated cryptography for digital signatures.
SV-205044r1137561_ruleThe ALG providing encryption intermediary services must use NIST FIPS-validated cryptography to implement encryption services.
SV-205045r831403_ruleThe ALG must off-load audit records onto a centralized log server in real time.
SV-205046r831404_ruleThe ALG that is part of a CDS must have the capability to implement journaling.
SV-205047r396516_ruleThe ALG must be configured in accordance with the security configuration settings based on DoD security policy and technology-specific security best practices.
SV-205048r396519_ruleThe ALG that provides intermediary services for SMTP must inspect inbound and outbound SMTP and Extended SMTP communications traffic for protocol compliance and protocol anomalies.
SV-205049r1138544_ruleThe ALG that provides intermediary services for FTP must inspect inbound and outbound FTP communications traffic for protocol compliance and protocol anomalies.
SV-205050r396525_ruleThe ALG that provides intermediary services for HTTP must inspect inbound and outbound HTTP traffic for protocol compliance and protocol anomalies.
SV-205051r396528_ruleThe ALG providing user access control intermediary services must generate audit records when successful/unsuccessful attempts to access privileges occur.
SV-205052r396531_ruleThe ALG providing user access control intermediary services must initiate a session lock after a 15-minute period of inactivity.
SV-205053r981648_ruleThe ALG providing user access control intermediary services must provide the capability for users to directly initiate a session lock.
SV-205054r396537_ruleThe ALG providing user access control intermediary services must retain the session lock until the user reestablishes access using established identification and authentication procedures.
SV-205055r831405_ruleThe ALG providing user access control intermediary services must automatically terminate a user session when organization-defined conditions or trigger events that require a session disconnect occur.
SV-205056r831406_ruleThe ALG providing user access control intermediary services must provide a logoff capability for user-initiated communications sessions.
SV-205057r831407_ruleThe ALG providing user access control intermediary services must display an explicit logoff message to users indicating the reliable termination of authenticated communications sessions.
SV-205058r396549_ruleThe ALG providing user access control intermediary services must conceal, via the session lock, information previously visible on the display with a publicly viewable image.
SV-263540r982391_ruleThe ALG must prevent or restrict changes to the configuration of the system under organization-defined circumstances.
SV-263541r981654_ruleThe ALG must employ organization-defined controls by type of denial of service (DoS) to achieve the DoS objective.
SV-263542r1137562_ruleThe ALG must implement physically or logically separate subnetworks to isolate organization-defined critical system components and functions.
SV-263543r981660_ruleThe ALG must implement antispoofing mechanisms to prevent adversaries from falsifying the security attributes indicating the successful application of the security process.
SV-263544r982395_ruleThe ALG must include only approved trust anchors in trust stores or certificate stores managed by the organization.
SV-263545r982397_ruleThe ALG must provide protected storage for cryptographic keys with organization-defined safeguards and/or hardware protected key store.
SV-263546r982399_ruleThe ALG must establish organization-defined alternate communications paths for system operations organizational command and control.
SV-263547r981672_ruleThe ALG must implement signature based and/or nonsignature based malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code.
SV-263548r982401_ruleThe ALG must configure malicious code protection mechanisms to send alerts to organization-defined personnel in response to malicious code detection.
SV-278954r1137565_ruleThe ALG must validate the integrity of transmitted security attributes.
SV-278955r1137568_ruleThe ALG must use cryptographic algorithms approved by NSA to protect NSS when transporting classified traffic across an unclassified network.
SV-278956r1137571_ruleThe ALG must be configured to use cryptographic algorithms approved by NSA to protect NSS for remote access to a classified network.
SV-278957r1137574_ruleThe ALG must use a FIPS-validated cryptographic module to provision digital signatures.
SV-278958r1137577_ruleThe ALG must use a FIPS-validated cryptographic module to implement encryption services for unclassified information requiring confidentiality.