SNMP is not being used in accordance with the Network Infrastructure STIG.

From Video Services Policy STIG

Part of RTS-VTC 3140.00 [IP]

Associated with IA controls: ECSC-1, DCBP-1

SV-18877r1_rule SNMP is not being used in accordance with the Network Infrastructure STIG.

Vulnerability discussion

Some VTC endpoints can be monitored using SNMP. It is also possible that if not today, in the future, VTC endpoints could be configured via SNMP. SNMP is typically used by vendor’s VTU/MCU management applications but it is conceivable that SNMP traps could be sent to any SNMP compatible network management system. At the time of this writing, applicable STIG requirements for the use of SNMP are contained in the Network Infrastructure STIG.

Check content

[IP]; Interview the IAO and validate compliance with the following requirement: If SNMP is used to monitor or remotely control/manage/configure a VTC system/device, ensure the use of SNMP is performed in compliance with the applicable SNMP requirements found in the Network Infrastructure STIG. This is a finding if SNMP is not being used in accordance with the Network Infrastructure STIG. Note: During APL testing, this is a finding in the event SNMP configuration cannot come into compliance with the Network Infrastructure STIG.

Fix text

[IP]; Perform the following tasks: If SNMP is used to monitor or remotely control/manage/configure a VTC system/device, implement and configure SNMP in compliance with the applicable SNMP requirements found in the Network Infrastructure STIG.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer