Out of band access is not utilized to access a test and development enclave remotely.

From Enclave - Zone C Checklist

Part of Out of band access is not utilized for T&D.

Associated with IA controls: ECSC-1

SV-3919r1_rule Out of band access is not utilized to access a test and development enclave remotely.

Vulnerability discussion

It is imperative that communications used for administrative access to test and development components is limited to emergency situations or where out-of-band management would hinder daily operational requirements. In-band management introduces the risk of an attacker gaining access to the network internally or even externally.

Check content

Interview the IAO to determine if they have a policy in place that requires the use of out-of-band methods to access a Test and Development network from outside of the enclave. Coordinate this response with the Network reviewer.

Fix text

The IAO will ensure that out-of-band access is utilized if outside access to the test and development systems is required

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer