STIGQter STIGQter: STIG Summary: IBM DataPower ALG Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 25 Jan 2016:

The DataPower Gateway providing user access control intermediary services must be configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or AAA server) which validate user account access authorizations and privileges.

DISA Rule

SV-79707r1_rule

Vulnerability Number

V-65217

Group Title

SRG-NET-000138-ALG-000088

Rule Version

WSDP-AG-000038

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Using the appliance's WebGUI, navigate to DataPower Gateway's Configure AAA Policy (authentication, authorization, audit) at Objects >> XML Processing >> AAA Policy.

On the Resource extraction tab, specify the correct resource information categories.

If there is a requirement for resource mapping, on the Resource mapping tab, specify the appropriate method and associated information.

On the Authorization tab, specify the correct methods, associated information and caching parameters.

Check Contents

Using the appliance's WebGUI, navigate to DataPower Gateway's Configure AAA Policy (authentication, authorization, audit) at Objects >> XML Processing >> AAA Policy.

On the Resource extraction tab, confirm that the correct resource information categories are checked.

If these items are not configured, this is a finding.

Vulnerability Number

V-65217

Documentable

False

Rule Version

WSDP-AG-000038

Severity Override Guidance

Using the appliance's WebGUI, navigate to DataPower Gateway's Configure AAA Policy (authentication, authorization, audit) at Objects >> XML Processing >> AAA Policy.

On the Resource extraction tab, confirm that the correct resource information categories are checked.

If these items are not configured, this is a finding.

Check Content Reference

M

Target Key

2859

Comments