SV-87737r1_rule
V-73085
NET-SDN-007
NET-SDN-007
CAT II
10
Deploy an out-of-band network to provision paths between management systems, orchestrations systems, and all hypervisor hosts that compose the SDN infrastructure to provide transport for southbound API management plane traffic.
An alternative is to encrypt all southbound API management plane traffic using a FIPS-validated cryptographic module. Implement a cryptographic module that has a validation certification and is listed on the NIST Cryptographic Module Validation Program's (CMVP) validation list.
Determine if the southbound API management plane traffic traverses an out-of-band path.
If not, verify that the southbound API management plane traffic is encrypted using a using a FIPS-validated cryptographic module.
If the southbound API management plane traffic does not traverse an out-of-band path or is not encrypted using a using a FIPS-validated cryptographic module, this is a finding.
V-73085
False
NET-SDN-007
Determine if the southbound API management plane traffic traverses an out-of-band path.
If not, verify that the southbound API management plane traffic is encrypted using a using a FIPS-validated cryptographic module.
If the southbound API management plane traffic does not traverse an out-of-band path or is not encrypted using a using a FIPS-validated cryptographic module, this is a finding.
M
3089