Skip to content

I - Mission Critical Public

Rules and Groups employed by this XCCDF Profile

  • SRG-NET-000510-ALG-000040

    <GroupDescription></GroupDescription>
    Group
  • Symantec ProxySG providing reverse proxy encryption intermediary services must implement NIST FIPS-validated cryptography for digital signatures.

    &lt;VulnDiscussion&gt;Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. The network elemen...
    Rule Medium Severity
  • SRG-NET-000510-ALG-000111

    <GroupDescription></GroupDescription>
    Group
  • Symantec ProxySG providing reverse proxy encryption intermediary services must use NIST FIPS-validated cryptography to implement encryption services.

    &lt;VulnDiscussion&gt;Use of weak or untested encryption algorithms undermines the purposes of using encryption to protect data. The network elemen...
    Rule Medium Severity
  • SRG-NET-000230-ALG-000113

    <GroupDescription></GroupDescription>
    Group
  • Symantec ProxySG must use Transport Layer Security (TLS) to protect the authenticity of communications sessions.

    &lt;VulnDiscussion&gt;Authenticity protection provides protection against man-in-the-middle attacks/session hijacking and the insertion of false in...
    Rule High Severity
  • SRG-NET-000355-ALG-000117

    <GroupDescription></GroupDescription>
    Group
  • If reverse proxy is used for validating and restricting certs from external entities, and this function is required by the SSP, Symantec ProxySG providing user authentication intermediary services using PKI-based user authentication must only accept end entity certificates issued by DoD PKI or DoD-approved PKI Certification Authorities (CAs) for the establishment of protected sessions.

    &lt;VulnDiscussion&gt;Non-DoD-approved PKIs have not been evaluated to ensure they have security controls and identity vetting procedures in place ...
    Rule Medium Severity
  • SRG-NET-000235-ALG-000118

    <GroupDescription></GroupDescription>
    Group
  • Symantec ProxySG must fail to a secure state upon failure of initialization, shutdown, or abort actions.

    &lt;VulnDiscussion&gt;Failure to a known safe state helps prevent systems from failing to a state that may cause loss of data or unauthorized acces...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules