Zone D systems have direct connectivity to a DoD network.

From Enclave - Zone D Checklist

Part of Zone D systems are connected to DoD network.

Associated with IA controls: EBCR-1

SV-14925r1_rule Zone D systems have direct connectivity to a DoD network.

Vulnerability discussion

Zone D is defined as an area for research and testing. The standalone system or collection of systems has no network connectivity outside of the physical space (except in rare cases where there is an ISP connection with ASD and GIG waiver approval). Zone D systems refer to a single system or collection of systems that have no network connectivity other than to themselves. The systems are all physically, not logically, connected and wholly contained/collocated within the facility. If the system is not physically connected to another system within the controlled environment it will not be network enabled. The stand-alone environment security controls are established at the discretion of the Enclave IAO or lab manager. Security requirements in the STIGs do not apply to stand-alone environments as those enclaves will not contain production or live DoD data and will not connect in any way to a DoD network.

Check content

Work with the network reviewer to determine if the Zone D environment has connection to any other network to include a DoD network. If Internet connectivity is desired for testing or research purposes, a DoD GIG Waiver must be issued for an Internet Service Provider (ISP) connection and the DISN CAP must be followed in order to obtain the waiver. See Network Infrastructure STIG.

Fix text

The IAO will ensure Zone D systems do not have any direct connectivity to a DoD network.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer