STIGQter STIGQter: STIG Summary: Infoblox 8.x DNS Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 09 Jan 2021:

The Infoblox system must display the appropriate security classification information.

DISA Rule

SV-233886r621666_rule

Vulnerability Number

V-233886

Group Title

SRG-APP-000516-DNS-000500

Rule Version

IDNS-8X-400028

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Navigate to Grid >> Grid Manager >> Grid Properties, or System >> System Manager >> System Properties if using a stand-alone configuration.
2. Select the "Security", "Advanced" tab. Click "Enable Security Banner".
3. Use the drop-down menus to select the Security Level and Security Level Color appropriate for each level.
4. Additional text can be entered if required by DoD or local policy.
5. When complete, click "Save & Close" to save the changes and exit the "Properties" screen.
6. Administrators should log out and close the web browser.
7. It may be necessary to clear the web browser cache for the banner to display or update on a session opened shortly after reconfiguration.

Check Contents

1. Log on to the Infoblox Grid Master or stand-alone system.
2. The appropriate security classification color and text must be displayed on the top of each configuration screen.
3. The output will also contain the text "Dynamic Page - Highest Possible Classification Is" and a colored bar associated with the classification.
4. Additional text may appear if configured by the administrator.

If the security classification color and text are not displayed at the top of each configuration screen, this is a finding.

Vulnerability Number

V-233886

Documentable

False

Rule Version

IDNS-8X-400028

Severity Override Guidance

1. Log on to the Infoblox Grid Master or stand-alone system.
2. The appropriate security classification color and text must be displayed on the top of each configuration screen.
3. The output will also contain the text "Dynamic Page - Highest Possible Classification Is" and a colored bar associated with the classification.
4. Additional text may appear if configured by the administrator.

If the security classification color and text are not displayed at the top of each configuration screen, this is a finding.

Check Content Reference

M

Target Key

5251

Comments