STIGQter STIGQter: STIG Summary:

Network Infrastructure Policy Security Technical Implementation Guide

Version: 10

Release: 7 Benchmark Date: 24 Oct 2024

CheckedNameTitle
SV-251333r877971_ruleWritten mission justification approval must be obtained from the Office of the DoD CIO prior to establishing a direct connection to the Internet via commercial service provider outside DoD CIO approved Internet access points (e.g. DISA IAP, Cloud Access Point, NIPRnet Federated Gateway, DREN IAP, etc.).
SV-251334r805957_ruleThe connection between the Channel Service Unit/Data Service Unit (CSU/DSU) and the Local Exchange Carriers (LEC) data service jack (i.e., demarc) as well as any service provider premise equipment must be located in a secure environment.
SV-251335r853642_ruleAn Intrusion Detection and Prevention System (IDPS) sensor must be deployed to monitor all Demilitarized Zone (DMZ) segments housing public servers.
SV-251336r853643_ruleAn Intrusion Detection and Prevention System (IDPS) sensor must be deployed to monitor the network segment hosting web, application, and database servers.
SV-251337r853644_ruleAn Intrusion Detection and Prevention System (IDPS) sensor must be deployed to monitor network segments that house network security management servers.
SV-251338r1007842_ruleAn Intrusion Detection and Prevention System (IDPS) must be deployed to monitor all unencrypted traffic entering and leaving the enclave.
SV-251339r805972_ruleSensor traffic in transit must be protected at all times via an Out-of-Band (OOB) network or an encrypted tunnel between site locations.
SV-251340r805975_ruleIntrusion Detection and Prevention System (IDPS) traffic between the sensor and the security management or sensor data collection servers must traverse a dedicated Virtual Local Area Network (VLAN) logically separating IDPS traffic from all other enclave traffic.
SV-251341r805978_ruleProducts collecting baselines for anomaly-based detection must have their baselines rebuilt based on changes to mission requirements such as Information Operations Conditions (INFOCON) levels and when the traffic patterns are expected to change significantly.
SV-251342r805981_ruleIf a Secure File Transfer Protocol (SFTP) server is used to provide updates to the sensors, the server must be configured to allow read-only access to the files within the directory on which the signature packs are placed.
SV-251343r805984_ruleIf an automated scheduler is used to provide updates to the sensors, an account on the file server must be defined that will provide access to the signatures only to the sensors.
SV-251344r805987_ruleThe Intrusion Detection and Prevention System (IDPS) configuration must be backed up before applying software or signature updates, or when making changes to the configuration.
SV-251345r805990_ruleThe Intrusion Detection and Prevention System (IDPS) file checksums provided by the vendor must be compared and verified with checksums computed from CD or downloaded files.
SV-251346r805993_ruleThe organization must establish weekly data backup procedures for the network Intrusion Detection and Prevention System (IDPS) data.
SV-251347r805996_ruleThe Intrusion Detection and Prevention System (IDPS) software and signatures must be updated when updates are provided by the vendor.
SV-251348r819076_ruleEncapsulated and/or encrypted traffic received from another enclave must not bypass the network perimeter defense without being terminated and inspected before entering the enclaves private network.
SV-251349r916231_ruleTunneling of classified traffic across an unclassified IP transport network or service provider backbone must be documented in the enclaves security authorization package and an Approval to Connect (ATC), or an Interim ATC must be issued by DISA prior to implementation.
SV-251350r877972_ruleDSAWG approval must be obtained before tunneling classified traffic outside the components local area network boundaries across a non-DISN or OCONUS DISN unclassified IP wide area network transport infrastructure.
SV-251351r916232_ruleTunneling of classified traffic across an unclassified IP transport network must employ cryptographic algorithms in accordance with CNSS Policy No. 15.
SV-251352r806011_ruleThe organization must ensure all switches and associated cross-connect hardware are kept in a secure Intermediate Distribution Frame (IDF) or an enclosed cabinet that is kept locked.
SV-251353r806014_ruleNetwork topology diagrams for the enclave must be maintained and up to date at all times.
SV-251354r806017_ruleAll external connections must be validated and approved by the Authorizing Official (AO) and the Connection Approval Office (CAO) and meeting Connection Approval Process (CAP) requirements.
SV-251355r806020_rulePrior to having external connection provisioned between enclaves, a Memorandum of Agreement (MOA) or Memorandum of Understanding (MOU) must be established.
SV-251356r806023_ruleExternal connections to the network must be reviewed and the documentation updated semi-annually.
SV-251357r806026_ruleIf the site has a non-DoD external connection (i.e. Approved Gateway), an Intrusion Detection and Prevention System (IDPS) must be located between the sites Approved Gateway and the perimeter router.
SV-251358r806029_ruleExternal network connections must not bypass the enclaves perimeter security.
SV-251359r877974_ruleAll global address ranges used on unclassified and classified networks must be properly registered with the DoD Network Information Center (NIC).
SV-251360r808530_ruleNetwork Address Translation (NAT) and private IP address space must not be deployed within the SIPRNet enclave.
SV-251361r853649_ruleDynamic Host Configuration Protocol (DHCP) audit and event logs must record sufficient forensic data to be stored online for thirty days and offline for one year.
SV-251362r853650_ruleDynamic Host Configuration Protocol (DHCP) servers used within SIPRNet infrastructure must be configured with a minimum lease duration time of 30 days.
SV-251363r806044_ruleAll network infrastructure devices must be located in a secure room with limited access.
SV-251364r853651_ruleAll hosted NIPRNet-only applications must be located in a local enclave Demilitarized Zone (DMZ).
SV-251365r806050_ruleAll Internet-facing applications must be hosted in a DoD Demilitarized Zone (DMZ) Extension.
SV-251366r853652_ruleWhen protecting the boundaries of a network, the firewall must be placed between the private network and the perimeter router and the Demilitarized Zone (DMZ).
SV-251367r806056_ruleThe organization must implement a deep packet inspection solution when protecting perimeter boundaries.
SV-251368r853653_ruleA deny-by-default security posture must be implemented for traffic entering and leaving the enclave.
SV-251369r806062_ruleTwo-factor authentication must be implemented to restrict access to all network elements.
SV-251370r806065_ruleTwo Network Time Protocol (NTP) servers must be deployed in the management network.
SV-251371r806068_ruleA policy must be implemented to keep Bogon/Martian rulesets up to date.
SV-251372r806071_ruleA dedicated management network must be implemented.
SV-251373r916119_ruleA minimum of two syslog servers must be deployed in the management network.
SV-251374r806077_ruleSyslog messages must be retained for a minimum of 30 days online and then stored offline for one year.
SV-251375r853654_ruleCurrent and previous network element configurations must be stored in a secured location.
SV-251376r853655_ruleThe organization must encrypt all network device configurations while stored offline.
SV-251377r808534_ruleAn Out-of-Band (OOB) management network must be deployed or 24x7 personnel must have console access for device management.
SV-251378r806089_ruleAll Releasable Local Area Network (REL LAN) environments must be documented in the System Security Authorization Agreement (SSAA).
SV-251379r806092_ruleAnnual reviews must be performed on all Releasable Local Area Network (REL LAN) environments.
SV-251380r806095_ruleEnabling a connection that extends DISN IP network connectivity (e.g., NIPRNet and SIPRNet) to any DoD Vendor, Foreign, or Federal Mission Partner enclave or network without a signed DoD CIO approved sponsorship memo is prohibited. For classified connectivity it must be to a DSS approved contractor facility or DoD Component approved foreign government facility.
SV-251381r806098_ruleCommand and Control (C2) and non-C2 exceptions of SIPRNet must be documented in the enclaves accreditation package and an Authority to Connect (ATC) or Interim ATC amending the connection approval received prior to implementation.
SV-251382r806101_ruleVPN gateways used to create IP tunnels to transport classified traffic across an unclassified IP network must comply with appropriate physical security protection standards for processing classified information.
SV-251383r806104_ruleMulti-Protocol Labeled Switching (MPLS) protocols deployed to build Label-Switch Path (LSP) tunnels must authenticate all messages with a hash function using the most secured cryptographic algorithm available.
SV-251384r806107_ruleMulti-Protocol Labeled Switching (MPLS) labels must not be exchanged between the enclaves edge routers and any external neighbor routers.
SV-251385r806110_ruleLabel Distribution Protocol (LDP) must be synchronized with the Interior Gateway Protocol (IGP) to minimize packet loss when an IGP adjacency is established prior to LDP peers completing label exchange.
SV-251386r806113_ruleRapid Spanning Tree Protocol (STP) must be implemented at the access and distribution layers where Virtual Local Area Networks (VLANs) span multiple switches.
SV-251387r806116_ruleA Quality of Service (QoS) policy must be implemented to provide preferred treatment for Command and Control (C2) real-time services and control plane traffic.
SV-251388r806119_ruleProtocol Independent Multicast (PIM) must be disabled on all router interfaces that are not required to support multicast routing.
SV-251389r806122_ruleA Protocol Independent Multicast (PIM) neighbor filter must be implemented to restrict and control multicast traffic.
SV-251390r806125_ruleThe multicast domain must block inbound and outbound administratively-scoped multicast traffic at the edge.
SV-251391r806128_ruleThe multicast domain must block inbound and outbound Auto-RP discovery and announcement messages at the edge.
SV-251392r806131_ruleProtocol Independent Multicast (PIM) register messages received from a downstream multicast Designated Routers (DR) must be filtered for any reserved or any other undesirable multicast groups.
SV-251393r806134_ruleProtocol Independent Multicast (PIM) join messages received from a downstream multicast Designated Routers (DR) must be filtered for any reserved or any other undesirable multicast groups.
SV-251394r853656_ruleMulticast register messages must be rate limited per each source-group (S, G) entry.
SV-251395r806140_ruleInternet Group Management Protocol (IGMP) and Multicast Listener Discovery (MLD) report messages must be filtered to allow hosts to join only those multicast groups that have been approved by the organization.
SV-251396r853657_ruleThe number of mroute states resulting from Internet Group Management Protocol (IGMP) or Multicast Listener Discovery (MLD) membership reports must be limited.
SV-251397r853658_ruleThe number of source-group (SG) states must be limited within the multicast topology where Any Source Multicast (ASM) is deployed.
SV-251398r853659_ruleInternet Group Management Protocol (IGMP) or Multicast Listener Discovery (MLD) snooping must be implemented within the network access layer.
SV-251399r806152_ruleFirst-hop redundancy services must be configured to delay any preempt to provide enough time for the Internet Gateway Protocol (IGP) to stabilize.