The personal firewall must be set to a minimum level of "Medium" or other designated intermediate setting or higher.

From Remote Endpoint STIG

Part of Personal firewall not configured to Medium

Associated with IA controls: ECSC-1

SV-6813r1_rule The personal firewall must be set to a minimum level of "Medium" or other designated intermediate setting or higher.

Vulnerability discussion

By setting the overall firewall to an intermediate/"Medium" or high, a protection mechanism is in place to protect the machine from malicious activity. (Remote Only)

Check content

This check verifies that the personal firewall security level is in compliance. The method of access to the firewall configuration will vary with the actual software. However, in general, the configuration can be viewed by clicking on the program icon in the desktop tray or by using the Programs menu. Navigate to the personal firewall Security Settings configuration window or tab and verify that the security level for both the Local and Internet Zones are set to intermediate setting of “Medium” or higher. The specific default intermediate settings may vary, depending on the vendor firewall used. At a minimum, this level of security should be customized to include the following: - Blocking all Internet access until expressly permitted by the user. - Silently block unused ports. - Block or prompt for usage of Java Applet and ActiveX controls. If the security level is not set to a minimum of intermediate or “Medium” and the above listed minimum settings are not in place, then mark this as a Category II finding.

Fix text

Ensure firewall is set to at least a medium level of security.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer