STIGQter STIGQter: STIG Summary: CA API Gateway ALG Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 28 Apr 2017:

The CA API Gateway providing user access control intermediary services must be configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or AAA server) that validate user account access authorizations and privileges.

DISA Rule

SV-85975r1_rule

Vulnerability Number

V-71351

Group Title

SRG-NET-000138-ALG-000088

Rule Version

CAGW-GW-000310

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Open the CA API Gateway - Policy Manager.

Select the "Identity Providers" tab, right-click "Identity Providers", and register the appropriate Identity Providers to establish the trust on the Gateway in accordance with organizational requirements.

Check Contents

Open the CA API Gateway - Policy Manager.

Select the "Identity Providers" tab and verify all appropriate Identity Providers are listed in accordance with organizational requirements.

If they are not, this is a finding.

Vulnerability Number

V-71351

Documentable

False

Rule Version

CAGW-GW-000310

Severity Override Guidance

Open the CA API Gateway - Policy Manager.

Select the "Identity Providers" tab and verify all appropriate Identity Providers are listed in accordance with organizational requirements.

If they are not, this is a finding.

Check Content Reference

M

Target Key

3049

Comments