STIGQter STIGQter: STIG Summary: Traditional Security Checklist Version: 1 Release: 3 Benchmark Date: 15 Jun 2020:

Protected Distribution System (PDS) Monitoring - Daily (Visual) Checks

DISA Rule

SV-41020r3_rule

Vulnerability Number

V-30976

Group Title

PDS Monitoring - Daily Visual Checks

Rule Version

CS-06.02.01

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

A PDS carrying SIPRNet cable is subject to periodic visual inspections IAW (Table 3. Visual Inspection Schedule, of CNSSI 7003). To correct this finding visual checks of PDS must be completed on a continuing basis as follows:

1. At least one daily inspection of the PDS line must be conducted, or more frequently if required by Table 3.

2. A log must be maintained of the PDS inspections. The log must contain the date of the inspection, the time of the inspection, the inspector’s name, and the inspector’s title. The log must be kept on record for a minimum of one year.

3. Person(s) must be formally appointed (in writing) to conduct the visual inspections.

4. The person(s) appointed to accomplish the visual inspection must be trained sufficiently to recognize physical changes in PDS including attempts at penetration and tampering.

5. That visual PDS inspections as detailed in Table 3 are conducted 365 days a year.

NOTES:

Visual inspections are not absolutely required for portions of PDS traversing a Secret or higher CAA but may be required by the AO.

In a tactical environment periodic visual checks are not applicable for Continuously Viewed Carriers since they are under continuous observation, 24 hours per day (including when operational). This check for visual inspections is only applicable to tactical environments where Hardened Carriers - versus Continuously Viewed Carriers - are used.

Check Contents

A PDS carrying SIPRNet cable is subject to periodic visual inspections IAW (Table 3. Visual Inspection Schedule, of CNSSI 7003). Check to ensure:

1. At least one daily inspection of the PDS line is conducted or more frequently if required by Table 3.

2. A log is maintained of the PDS inspections. The log must contain the date of the inspection, the time of the inspection, the inspector’s name, and the inspector’s title. The log must be kept on record for a minimum of one year.

3. Person(s) are formally appointed (in writing) to conduct the visual inspections.

4. The person(s) appointed to accomplish the visual inspection are trained sufficiently to recognize physical changes in PDS including attempts at penetration and tampering.

5. That visual PDS inspections as detailed in Table 3 are conducted 365 days a year.

NOTES:

Visual inspections are not absolutely required for portions of PDS traversing a Secret or higher CAA but may be required by the AO.

In a tactical environment periodic visual checks are not applicable for Continuously Viewed Carriers since they are under continuous observation, 24 hours per day (including when operational). This check for visual inspections is only applicable to tactical environments where Hardened Carriers - versus Continuously Viewed Carriers - are used.

Vulnerability Number

V-30976

Documentable

False

Rule Version

CS-06.02.01

Severity Override Guidance

A PDS carrying SIPRNet cable is subject to periodic visual inspections IAW (Table 3. Visual Inspection Schedule, of CNSSI 7003). Check to ensure:

1. At least one daily inspection of the PDS line is conducted or more frequently if required by Table 3.

2. A log is maintained of the PDS inspections. The log must contain the date of the inspection, the time of the inspection, the inspector’s name, and the inspector’s title. The log must be kept on record for a minimum of one year.

3. Person(s) are formally appointed (in writing) to conduct the visual inspections.

4. The person(s) appointed to accomplish the visual inspection are trained sufficiently to recognize physical changes in PDS including attempts at penetration and tampering.

5. That visual PDS inspections as detailed in Table 3 are conducted 365 days a year.

NOTES:

Visual inspections are not absolutely required for portions of PDS traversing a Secret or higher CAA but may be required by the AO.

In a tactical environment periodic visual checks are not applicable for Continuously Viewed Carriers since they are under continuous observation, 24 hours per day (including when operational). This check for visual inspections is only applicable to tactical environments where Hardened Carriers - versus Continuously Viewed Carriers - are used.

Check Content Reference

M

Target Key

2506

Comments