SV-222628r561275_rule
V-222628
SRG-APP-000516
APSC-DV-002980
CAT II
10
Verify the accreditation documentation lists all interfaces and the ports, protocols, and services used.
Verify that all ports, protocols, and services are used in accordance with the DoD PPSM.
All application ports, protocols, and services needed for application operation need to be in compliance with the DoD Ports and Protocols guidance.
Check:
http://iase.disa.mil/ppsm/Pages/index.aspx
to verify the ports, protocols, and services are in compliance with the PPS CAL.
Check all necessary ports and protocols needed for application operation (only those accessed from outside the local enclave) are checked against the DoD Ports and Protocols guidance to ensure compliance.
Identify the ports needed for the application:
- Look at System Security Plan/Accreditation documentation
- Ask System Administrator
- Go to Network Administrator
- Go to Network Reviewer
- If a network scan is available, use it
- Use netstat/task manager
- Check /etc./services
If the application is not in compliance with DoD Ports and Protocols guidance, this is a finding.
V-222628
False
APSC-DV-002980
All application ports, protocols, and services needed for application operation need to be in compliance with the DoD Ports and Protocols guidance.
Check:
http://iase.disa.mil/ppsm/Pages/index.aspx
to verify the ports, protocols, and services are in compliance with the PPS CAL.
Check all necessary ports and protocols needed for application operation (only those accessed from outside the local enclave) are checked against the DoD Ports and Protocols guidance to ensure compliance.
Identify the ports needed for the application:
- Look at System Security Plan/Accreditation documentation
- Ask System Administrator
- Go to Network Administrator
- Go to Network Reviewer
- If a network scan is available, use it
- Use netstat/task manager
- Check /etc./services
If the application is not in compliance with DoD Ports and Protocols guidance, this is a finding.
M
4093