SV-7005r2_rule
V-6783
MFD Management Protocols
MFD02.003
CAT II
10
Disable all management protocols except HTTPS and SNMPv3 unless approval has been granted by the organization's AO/ISSM.
Verify that all management protocols are disabled unless approved by the organization's AO/ISSM.
Protocols may be enabled temporarily if needed to upgrade firmware or configure the device, but must be disabled immediately when this activity is completed. HTTPS and SNMPv3 may be used but must be configured in accordance with the requirements of the Network Infrastructure STIG.
If management protocols other than HTTPS and SNMPv3 are enabled unnecessarily or without AO/ISSM approval, this is a finding.
V-6783
False
MFD02.003
Verify that all management protocols are disabled unless approved by the organization's AO/ISSM.
Protocols may be enabled temporarily if needed to upgrade firmware or configure the device, but must be disabled immediately when this activity is completed. HTTPS and SNMPv3 may be used but must be configured in accordance with the requirements of the Network Infrastructure STIG.
If management protocols other than HTTPS and SNMPv3 are enabled unnecessarily or without AO/ISSM approval, this is a finding.
M
System Administrator
551