Management protocols, with the exception of HTTPS and SNMPv3, must be disabled at all times except when necessary.

From Multifunction Device and Network Printers STIG

Part of MFD Management Protocols

Associated with IA controls: DCPP-1

SV-7005r2_rule Management protocols, with the exception of HTTPS and SNMPv3, must be disabled at all times except when necessary.

Vulnerability discussion

Unneeded protocols expose the device and the network to unnecessary vulnerabilities.

Check content

Verify that all management protocols are disabled unless approved by the organization's AO/ISSM. Protocols may be enabled temporarily if needed to upgrade firmware or configure the device, but must be disabled immediately when this activity is completed. HTTPS and SNMPv3 may be used but must be configured in accordance with the requirements of the Network Infrastructure STIG. If management protocols other than HTTPS and SNMPv3 are enabled unnecessarily or without AO/ISSM approval, this is a finding.

Fix text

Disable all management protocols except HTTPS and SNMPv3 unless approval has been granted by the organization's AO/ISSM.

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer