Information
A main security architectural construct of a PAW is that the workstation is isolated from most Internet threats, including phishing, impersonation, and credential theft attacks. This isolation is partially implemented by blocking unsolicited inbound traffic to the PAW.
NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.
Solution
Determine which inbound ports, services, addresses, or subnets are needed on the PAW for the organization's monitoring, scanning, and management tools.
Configure the host-based firewall on the PAW to block all inbound connection requests except for organizational monitoring, scanning, and management tools or for inbound connections that are responses to outbound connection requests.
Configure the host-based firewall on the PAW to block users with local administrative access from creating or modifying local firewall rules.
Note: The exact configuration procedure will depend on which host-based firewall (for example, ESS) is used on the PAW. DoD sites should refer to DoD policies and firewall STIGs to determine acceptable firewalls products.
Item Details
Category: CONFIGURATION MANAGEMENT, SYSTEM AND COMMUNICATIONS PROTECTION
References: 800-53|CM-6b., 800-53|SC-7(11), CAT|II, CCI|CCI-000366, CCI|CCI-002403, Rule-ID|SV-243460r991589_rule, STIG-ID|WPAW-00-002100, STIG-Legacy|SV-92887, STIG-Legacy|V-78181, Vuln-ID|V-243460
Control ID: 5e56f62dbe9eb4809178786e3f93460a49cd49a32a3fadd7b94e1636622f4c09