STIGQter STIGQter: STIG Summary: Citrix Virtual Apps and Desktop 7.x StoreFront Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 28 Jan 2021:

The Citrix Storefront server must implement DoD-approved encryption to protect the confidentiality of remote access sessions.

DISA Rule

SV-234251r628797_rule

Vulnerability Number

V-234251

Group Title

SRG-APP-000014

Rule Version

CVAD-SF-000030

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Implement a DoD approved VPN, or gateway/proxy, that will authenticate user access and tunnel/proxy traffic to StoreFront. Ensure the VPN, or gateway/proxy, is configured to authenticate the user before accessing the environment, and meets the DoD encryption requirements, such as FIPS 140-2, for the environment.

Check Contents

A DoD approved VPN, or gateway/proxy, must be leveraged to access StoreFront from a remote network. This VPN, or gateway, must handle user authentication and tunneling of StoreFront traffic. The VPN, or gateway, must meet the DoD encryption requirements, such as FIPS 140-2, for the environment.

If no VPN, or gateway/proxy, is used for remote access to StoreFront, this is a finding.
If the VPN, or gateway/proxy, does not authenticate the remote user before providing access to StoreFront, this is a finding.
If the VPN, or gateway/proxy, fails to meet the DoD encryption requirements for the environment, this is a finding.

Vulnerability Number

V-234251

Documentable

False

Rule Version

CVAD-SF-000030

Severity Override Guidance

A DoD approved VPN, or gateway/proxy, must be leveraged to access StoreFront from a remote network. This VPN, or gateway, must handle user authentication and tunneling of StoreFront traffic. The VPN, or gateway, must meet the DoD encryption requirements, such as FIPS 140-2, for the environment.

If no VPN, or gateway/proxy, is used for remote access to StoreFront, this is a finding.
If the VPN, or gateway/proxy, does not authenticate the remote user before providing access to StoreFront, this is a finding.
If the VPN, or gateway/proxy, fails to meet the DoD encryption requirements for the environment, this is a finding.

Check Content Reference

M

Target Key

5264

Comments