Skip to content

II - Mission Support Classified

Rules and Groups employed by this XCCDF Profile

  • SRG-NET-000383-ALG-000135

    Group
  • The A10 Networks ADC, when used to load balance web applications, must enable external logging for WAF data event messages.

    Without coordinated reporting between separate devices, it is not possible to identify the true scale and possible target of an attack. External logging must be enabled for WAF data event messages...
    Rule Low Severity
  • SRG-NET-000392-ALG-000141

    Group
  • The A10 Networks ADC must enable logging for packet anomaly events.

    Without an alert, security personnel may be unaware of major detection incidents that require immediate action and this delay may result in the loss or compromise of information. Since these incide...
    Rule Medium Severity
  • SRG-NET-000392-ALG-000142

    Group
  • The A10 Networks ADC must generate an alert to, at a minimum, the ISSO and ISSM when threats identified by authoritative sources (e.g., IAVMs or CTOs) are detected.

    Without an alert, security personnel may be unaware of major detection incidents that require immediate action and this delay may result in the loss or compromise of information. The device genera...
    Rule Medium Severity
  • SRG-NET-000392-ALG-000148

    Group
  • The A10 Networks ADC must enable logging of Denial of Service (DoS) attacks.

    Without an alert, security personnel may be unaware of major detection incidents that require immediate action, and this delay may result in the loss or compromise of information. CJCSM 6510.01B, "...
    Rule Medium Severity
  • SRG-NET-000401-ALG-000127

    Group
  • The A10 Networks ADC, when used for load-balancing web servers, must not allow the HTTP TRACE and OPTIONS methods.

    HTTP offers a number of methods that can be used to perform actions on the web server. Some of these HTTP methods can be used for nefarious purposes if the web server is misconfigured. The two HTTP...
    Rule Medium Severity
  • SRG-NET-000402-ALG-000130

    Group
  • The A10 Networks ADC must reveal error messages only to authorized individuals (ISSO, ISSM, and SA).

    Only authorized personnel should be aware of errors and the details of the errors. Error messages are an indicator of an organization's operational state or can give configuration details about the...
    Rule Medium Severity
  • SRG-NET-000511-ALG-000051

    Group
  • The A10 Networks ADC must, at a minimum, off-load audit log records onto a centralized log server.

    Off-loading ensures audit information does not get overwritten if the limited audit storage capacity is reached and also protects the audit record in case the system/component being audited is comp...
    Rule Low Severity
  • SRG-NET-000512-ALG-000062

    Group
  • The A10 Networks ADC, when used for load balancing web servers, must deploy the WAF in active mode.

    The Web Application Firewall (WAF) supports three operational modes - Learning, Passive, and Active. Active is the standard operational mode and must be used in order to drop or sanitize traffic. L...
    Rule Medium Severity
  • SRG-NET-000512-ALG-000062

    Group
  • If the Data Owner requires it, the A10 Networks ADC must be configured to perform CCN Mask, SSN Mask, and PCRE Mask Request checks.

    If outbound communications traffic is not continuously monitored, hostile activity may not be detected and prevented. Output from application and traffic monitoring serves as input to continuous mo...
    Rule Medium Severity
  • SRG-NET-000362-ALG-000112

    Group
  • The A10 Networks ADC must protect against ICMP-based Denial of Service (DoS) attacks by employing ICMP Rate Limiting.

    If the network does not provide safeguards against DoS attacks, network resources will be unavailable to users. Installation of content filtering gateways and application layer firewalls at key bou...
    Rule High Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules