III - Administrative Classified
Rules and Groups employed by this XCCDF Profile
-
SRG-NET-000019-ALG-000018
<GroupDescription></GroupDescription>Group -
The BIG-IP AFM module must be configured to restrict or block harmful or suspicious communications traffic by controlling the flow of information between interconnected networks based on attribute- and content-based inspection of the source, destination, headers, and/or content of the communications traffic.
<VulnDiscussion>Information flow control regulates where information is allowed to travel within a network and between interconnected network...Rule High Severity -
SRG-NET-000074-ALG-000043
<GroupDescription></GroupDescription>Group -
The BIG-IP AFM module must be configured to produce audit records containing information to establish what type of events occurred.
<VulnDiscussion>Without establishing what type of event occurred, it would be difficult to establish, correlate, and investigate the events l...Rule Medium Severity -
SRG-NET-000364-ALG-000122
<GroupDescription></GroupDescription>Group -
The BIG-IP AFM module must be configured to only allow incoming communications from authorized sources routed to authorized destinations.
<VulnDiscussion>Unrestricted traffic may contain malicious traffic that poses a threat to an enclave or to other connected networks. Addition...Rule Medium Severity -
SRG-NET-000380-ALG-000128
<GroupDescription></GroupDescription>Group -
The BIG-IP AFM module must be configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives.
<VulnDiscussion>A common vulnerability of network elements is unpredictable behavior when invalid inputs are received. This requirement guard...Rule Medium Severity
Node 2
The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.