Tamper resistant seals are not attached to the KVM switch and all IS cables at their attachment points where the KVM switch is attached to ISs of different classification levels.

From Keyboard, Video, Mouse Switch Security STIG

Part of KVM Spaning Classification Level Tamper Seals

Associated with IA controls: DCBP-1

SV-6882r1_rule Tamper resistant seals are not attached to the KVM switch and all IS cables at their attachment points where the KVM switch is attached to ISs of different classification levels.

Vulnerability discussion

Tamper resistant seals are tape designed to break if tampered with. They are used to indicate that a cabinet has been opened or a cable removed, moved or added. For KVM switches attached to ISs of differing classification levels it is necessary to be aware of any potential tampering with the connections. Switching the cables for two ISs could lead to the compromise of sensitive data. Removal of a cable could lead to a denial of service until it is reattached.The IAO or SA will ensure that tamper resistant seals are attached to the KVM switch and all IS cables at their attachment points.

Check content

The reviewer will verify that tamper resistant seals are attached to the KVM switches and to the IS cable attachment points. For cables these seals will be place across the junction between the switch and the cable. For the KVM witch the seals will be placed across the KVM case joints so that opening the case will break the seal.

Fix text

Obtain tamper resistant seals and apply them to the KVM switch case joints so that if the case is open the seal will be broken. Also place them across the junction between the IS cables and the KVM switch so that if a cable is moved or removed the seal will be broken.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer