SOL-11.1-060110 - The operating system must employ cryptographic mechanisms to prevent unauthorized disclosure of information during transmission unless otherwise protected by alternative physical measures.

Information

Ensuring that transmitted information does not become disclosed to unauthorized entities requires the operating system take feasible measures to employ transmission layer security. This requirement applies to communications across internal and external networks.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

All remote sessions must be conducted via SSH and IPsec. Ensure that SSH and IPsec are the only protocols used.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_11_SPARC_V2R9_STIG.zip

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-8(1), CAT|II, CCI|CCI-002421, Rule-ID|SV-219980r877040_rule, STIG-ID|SOL-11.1-060110, STIG-Legacy|SV-61035, STIG-Legacy|V-48163, Vuln-ID|V-219980

Plugin: Unix

Control ID: d5489254829bfe29e12353dae785775e3750c853d8ffda15b497f10f4681bace