I - Mission Critical Public
Rules and Groups employed by this XCCDF Profile
-
SRG-NET-000077-ALG-000046
Group -
The A10 Networks ADC, when used to load balance web applications, must enable external logging for accessing Web Application Firewall data event messages.
Without establishing where events occurred, it is impossible to establish, correlate, and investigate the events leading up to an outage or attack. External logging must be enabled for WAF data ev...Rule Low Severity -
SRG-NET-000088-ALG-000054
Group -
The A10 Networks ADC must send an alert to, at a minimum, the ISSO and SCA when connectivity to the Syslog servers is lost.
It is critical for the appropriate personnel to be aware if a system is at risk of failing to process audit logs as required. Without this notification, the security personnel may be unaware of an ...Rule Low Severity -
SRG-NET-000131-ALG-000085
Group -
The A10 Networks ADC must not have unnecessary scripts installed.
Information systems are capable of providing a wide variety of functions (capabilities or processes) and services. Some of these functions and services are installed and enabled by default. The org...Rule Medium Severity -
SRG-NET-000131-ALG-000086
Group -
The A10 Networks ADC must use DNS Proxy mode when Global Server Load Balancing is used.
Unrelated or unneeded proxy services increase the attack vector and add excessive complexity to the securing of the device. Multiple application proxies can be installed on many devices. However, p...Rule Medium Severity -
SRG-NET-000132-ALG-000087
Group -
The A10 Networks ADC must be configured to prohibit or restrict the use of functions, ports, protocols, and/or services as defined in the PPSM CAL and vulnerability assessments.
In order to prevent unauthorized connection of devices, unauthorized transfer of information, or unauthorized tunneling (i.e., embedding of data types within data types); organizations must disable...Rule Medium Severity -
SRG-NET-000164-ALG-000100
Group -
The A10 Networks ADC when used for TLS encryption and decryption must validate certificates used for TLS functions by performing RFC 5280-compliant certification path validation.
A certificate's certification path is the path from the end entity certificate to a trusted root certification authority (CA). Certification path validation is necessary for a relying party to make...Rule Medium Severity -
SRG-NET-000202-ALG-000124
Group -
The A10 Networks ADC must not have any unnecessary or unapproved virtual servers configured.
A deny-all, permit-by-exception network communications traffic policy ensures that only those connections which are essential and approved are allowed. A virtual server is an instance where the de...Rule Medium Severity -
SRG-NET-000273-ALG-000129
Group -
The A10 Networks ADC, when used to load balance web applications, must strip HTTP response headers.
Providing too much information in error messages risks compromising the data and security of the application and system. HTTP response headers can disclose vulnerabilities about a web server. This ...Rule Medium Severity -
SRG-NET-000273-ALG-000129
Group -
The A10 Networks ADC, when used to load balance web applications, must replace response codes.
Providing too much information in error messages risks compromising the data and security of the application and system. HTTP response codes can be used by an attacker to learn how a web server res...Rule Medium Severity -
SRG-NET-000318-ALG-000014
Group -
To protect against data mining, the A10 Networks ADC must detect and prevent SQL and other code injection attacks launched against data storage objects, including, at a minimum, databases, database records, queries, and fields.
Data mining is the analysis of large quantities of data to discover patterns and is used in intelligence gathering. Failure to prevent attacks launched against organizational information from unaut...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.