STIGQter STIGQter: STIG Summary: Application Layer Gateway (ALG) Security Requirements Guide (SRG) Version: 1 Release: 2 Benchmark Date: 24 Jul 2015:

The ALG that is part of a CDS, when transferring information between different security domains, must apply the same security policy filtering to metadata as it applies to data payloads.

DISA Rule

SV-68731r1_rule

Vulnerability Number

V-54485

Group Title

SRG-NET-000328-ALG-000078

Rule Version

SRG-NET-000328-ALG-000078

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If the ALG is part of a CDS, configure the ALG to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains.

Check Contents

If the ALG is not part of a CDS, this is not applicable.

Verify the ALG is configured to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains.

If the ALG is not configured to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains, this is a finding.

Vulnerability Number

V-54485

Documentable

False

Rule Version

SRG-NET-000328-ALG-000078

Severity Override Guidance

If the ALG is not part of a CDS, this is not applicable.

Verify the ALG is configured to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains.

If the ALG is not configured to apply the same security policy filtering to metadata as it applies to data payloads when transferring information between different security domains, this is a finding.

Check Content Reference

M

Target Key

2489

Comments