II - Mission Support Classified
Rules and Groups employed by this XCCDF Profile
-
NET0346
Group -
All hosted NIPRNet-only applications must be located in a local enclave Demilitarized Zone (DMZ).
Without the protection of a DMZ, production networks will be prone to outside attacks as they are allowing externally accessible services to be accessed on the internal LAN. This can cause many un...Rule Medium Severity -
NET0348
Group -
All Internet-facing applications must be hosted in a DoD Demilitarized Zone (DMZ) Extension.
Without the protection of a DMZ, production networks will be prone to outside attacks as they are allowing externally accessible services to be accessed on the internal LAN. This can cause many un...Rule Medium Severity -
NET0351
Group -
When protecting the boundaries of a network, the firewall must be placed between the private network and the perimeter router and the Demilitarized Zone (DMZ).
The only way to mediate the flow of traffic between the inside network, the outside connection, and the DMZ is to place the firewall into the architecture in a manner that allows the firewall the a...Rule Medium Severity -
NET0365
Group -
The organization must implement a deep packet inspection solution when protecting perimeter boundaries.
Deep packet inspection (DPI) examines the packet beyond the Layer 4 header by examining the payload to identify the application or service. DPI searches for illegal statements, predefined criteria,...Rule High Severity -
NET0369
Group -
A deny-by-default security posture must be implemented for traffic entering and leaving the enclave.
To prevent malicious or accidental leakage of traffic, organizations must implement a deny-by-default security posture at the network perimeter. Such rulesets prevent many malicious exploits or ac...Rule High Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.