Skip to content

III - Administrative Public

Rules and Groups employed by this XCCDF Profile

  • NET-SDN-002

    Group
  • Northbound API traffic received by the SDN controller must be authenticated using a FIPS-approved message authentication code algorithm.

    The SDN controller determines how traffic should flow through physical and virtual network devices based on application profiles, network infrastructure resources, security policies, and business r...
    Rule High Severity
  • NET-SDN-003

    Group
  • Access to the SDN management and orchestration systems must be authenticated using a FIPS-approved message authentication code algorithm.

    The SDN controller receives network service requests from orchestration and management systems to deploy and configure network elements via the northbound API. In turn, the Northbound API presents ...
    Rule Medium Severity
  • NET-SDN-004

    Group
  • Southbound API control plane traffic must traverse an out-of-band path or be encrypted using a FIPS-validated cryptographic module.

    Southbound APIs such as OpenFlow provide the forwarding tables to network devices such as switches and routers, both physical and virtual (hypervisor-based). The SDN controllers use the concept of ...
    Rule High Severity
  • NET-SDN-005

    Group
  • Northbound API traffic must traverse an out-of-band path or be encrypted using a FIPS-validated cryptographic module.

    The SDN controller receives network service requests from orchestration and management systems to deploy and configure network elements via the northbound API. In turn, the northbound API presents ...
    Rule High Severity
  • NET-SDN-006

    Group
  • Southbound API management plane traffic for provisioning and configuring virtual network elements within the SDN infrastructure must be authenticated using a FIPS-approved message authentication code algorithm.

    Management and orchestration systems within the SDN framework instantiate, deploy, and configure virtual network elements. These systems also define the virtual network topology by specifying the c...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules