The organization must comply with DoD ports and protocol guidance within the information system deemed to be non-secure for remote access into DoD networks.

From Mobile Policy Security Requirements Guide

Part of SRG-MPOL-002

Associated with: CCI-001435

SV-47227r2_rule The organization must comply with DoD ports and protocol guidance within the information system deemed to be non-secure for remote access into DoD networks.

Vulnerability discussion

Some networking protocols are considered less secure than others (e.g., Bluetooth, peer-to-peer, etc.). In its access control policy and security procedures addressing remote access to the information system, the organization, in order to protect and secure its network, must define those network protocols considered to be non-secure. Failure to define the non-secure network protocols could result in the organization's network being open to access by these non-secure protocols, which could result in unauthorized access to, modification of, or destruction of sensitive or classified data. For mobile systems, several non-secure protocols are used routinely in the commercial world. Many of these must not be allowed on DoD networks and specified.

Check content

Review the organization's policies related to network protocols. The organization must document those networking protocols within the information system deemed to be non-secure for remote access into DoD networks. If the policies do not specifically list non-secure protocols, this is a finding.

Fix text

Create and document a list of networking protocols within the information system deemed to be non-secure for remote access into DoD networks.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer