SV-234251r628797_rule
V-234251
SRG-APP-000014
CVAD-SF-000030
CAT I
10
Implement a DoD approved VPN, or gateway/proxy, that will authenticate user access and tunnel/proxy traffic to StoreFront. Ensure the VPN, or gateway/proxy, is configured to authenticate the user before accessing the environment, and meets the DoD encryption requirements, such as FIPS 140-2, for the environment.
A DoD approved VPN, or gateway/proxy, must be leveraged to access StoreFront from a remote network. This VPN, or gateway, must handle user authentication and tunneling of StoreFront traffic. The VPN, or gateway, must meet the DoD encryption requirements, such as FIPS 140-2, for the environment.
If no VPN, or gateway/proxy, is used for remote access to StoreFront, this is a finding.
If the VPN, or gateway/proxy, does not authenticate the remote user before providing access to StoreFront, this is a finding.
If the VPN, or gateway/proxy, fails to meet the DoD encryption requirements for the environment, this is a finding.
V-234251
False
CVAD-SF-000030
A DoD approved VPN, or gateway/proxy, must be leveraged to access StoreFront from a remote network. This VPN, or gateway, must handle user authentication and tunneling of StoreFront traffic. The VPN, or gateway, must meet the DoD encryption requirements, such as FIPS 140-2, for the environment.
If no VPN, or gateway/proxy, is used for remote access to StoreFront, this is a finding.
If the VPN, or gateway/proxy, does not authenticate the remote user before providing access to StoreFront, this is a finding.
If the VPN, or gateway/proxy, fails to meet the DoD encryption requirements for the environment, this is a finding.
M
5264