SV-80007r2_rule
V-65517
SRG-APP-000416
AGIS-00-000187
CAT I
10
Configure the ArcGIS Server to implement NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. Substitute the target environment’s values for [bracketed] variables.
Within IIS >> within the "[arcgis]" application >> SSL Settings >> check "Require SSL".
Review the ArcGIS Server configuration to ensure the application implements NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. Substitute the target environment’s values for [bracketed] variables.
Within IIS >> within the [“arcgis”] application >> SSL Settings >> Verify that “Require SSL” is checked.
If “Require SSL” is not checked, this is a finding.
Note: To comply with this control, the Active Directory domain on which the ArcGIS Server and the IIS system are deployed must implement policies which enforce FIPS 140-2 compliance.
This control is not applicable for ArcGIS Servers which are deployed as part of a solution which ensures user web service traffic flows through third-party DoD compliant transport encryption devices (such as a load balancer that supports TLS encryption using DoD-approved certificates.)
This control is not applicable for ArcGIS Servers which are not deployed with the ArcGIS Web Adapter component.
V-65517
False
AGIS-00-000187
Review the ArcGIS Server configuration to ensure the application implements NSA-approved cryptography to protect classified information in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, and standards. Substitute the target environment’s values for [bracketed] variables.
Within IIS >> within the [“arcgis”] application >> SSL Settings >> Verify that “Require SSL” is checked.
If “Require SSL” is not checked, this is a finding.
Note: To comply with this control, the Active Directory domain on which the ArcGIS Server and the IIS system are deployed must implement policies which enforce FIPS 140-2 compliance.
This control is not applicable for ArcGIS Servers which are deployed as part of a solution which ensures user web service traffic flows through third-party DoD compliant transport encryption devices (such as a load balancer that supports TLS encryption using DoD-approved certificates.)
This control is not applicable for ArcGIS Servers which are not deployed with the ArcGIS Web Adapter component.
M
2961