Skip to content

II - Mission Support Public

Rules and Groups employed by this XCCDF Profile

  • NET0346

    <GroupDescription></GroupDescription>
    Group
  • All hosted NIPRNet-only applications must be located in a local enclave Demilitarized Zone (DMZ).

    &lt;VulnDiscussion&gt;Without the protection of a DMZ, production networks will be prone to outside attacks as they are allowing externally accessi...
    Rule Medium Severity
  • NET0348

    <GroupDescription></GroupDescription>
    Group
  • All Internet-facing applications must be hosted in a DoD Demilitarized Zone (DMZ) Extension.

    &lt;VulnDiscussion&gt;Without the protection of a DMZ, production networks will be prone to outside attacks as they are allowing externally accessi...
    Rule Medium Severity
  • NET0351

    <GroupDescription></GroupDescription>
    Group
  • When protecting the boundaries of a network, the firewall must be placed between the private network and the perimeter router and the Demilitarized Zone (DMZ).

    &lt;VulnDiscussion&gt;The only way to mediate the flow of traffic between the inside network, the outside connection, and the DMZ is to place the f...
    Rule Medium Severity
  • NET0365

    <GroupDescription></GroupDescription>
    Group
  • The organization must implement a deep packet inspection solution when protecting perimeter boundaries.

    &lt;VulnDiscussion&gt;Deep packet inspection (DPI) examines the packet beyond the Layer 4 header by examining the payload to identify the applicati...
    Rule High Severity
  • NET0369

    <GroupDescription></GroupDescription>
    Group
  • A deny-by-default security posture must be implemented for traffic entering and leaving the enclave.

    &lt;VulnDiscussion&gt;To prevent malicious or accidental leakage of traffic, organizations must implement a deny-by-default security posture at the...
    Rule High Severity
  • NET0445

    <GroupDescription></GroupDescription>
    Group
  • Two-factor authentication must be implemented to restrict access to all network elements.

    &lt;VulnDiscussion&gt;Without secure management implemented with authenticated access controls, strong two-factor authentication, encryption of the...
    Rule Medium Severity
  • NET0810

    <GroupDescription></GroupDescription>
    Group
  • Two Network Time Protocol (NTP) servers must be deployed in the management network.

    &lt;VulnDiscussion&gt;NTP provides an efficient and scalable method for managed network elements to actively synchronize to an accurate time source...
    Rule Low Severity
  • NET0928

    <GroupDescription></GroupDescription>
    Group
  • A policy must be implemented to keep Bogon/Martian rulesets up to date.

    &lt;VulnDiscussion&gt;A Bogon route or Martian address is a type of packet that should never be routed inbound through the perimeter device. Bogon...
    Rule Medium Severity
  • NET0998

    <GroupDescription></GroupDescription>
    Group
  • A dedicated management network must be implemented.

    &lt;VulnDiscussion&gt;To deploy a management network for the purpose of controlling, monitoring, and restricting management traffic, a separate man...
    Rule Medium Severity
  • NET1025

    <GroupDescription></GroupDescription>
    Group
  • A minimum of two syslog servers must be deployed in the management network.

    &lt;VulnDiscussion&gt;Maintaining an audit trail of system activity logs can help identify configuration errors, understand past intrusions, troubl...
    Rule Low Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules