Search filters the loaded procedure list locally. Separate terms must all match (use quotes for an exact phrase). Cached STIG Search results apply when you arrive from Search.
Objective ID
Severity
Discussion
V-284581
high
Successful authentication must not automatically give an entity access to an asset or security boundary. The lack of authorization-based access control could result in the immediate compromise and unauthorized access to sensitive information.
Authorization is the process of determining whether an entity, once authenticated, is permitted to access a specific asset. Many NACs include the ability to create network access control policies that include identity-based policies, role-based policies, and attribute-based policies.
It is recommended the NAC have the capability to expose collected data on the assessed endpoints through an API that can be accessed externally, or the NAC solution must supply an SDK to allow customers to export data.
Admissions assessment filters should include, at a minimum, device attributes such as type, IP address, resource group, and/or mission conditions as defined in the NAC SSP. The NAC should also track the following to facilitate security investigations: when each device was last admitted/readmitted to the network; owning organization; owning organization's organizational unit; geographic location or the nearest network switch; motherboard serial number and BIOS; globally unique ID; and which unique network access compliance policies each device passed or failed during the latest network admission/readmission.
The client may be denied admission based on a returned posture token. In most NAC implementations, additional network access authorization policies can also be tied to the user's identity, but these features are out of scope for this STIG.
Authorization is the process of determining whether an entity, once authenticated, is permitted to access a specific asset. Many NACs include the ability to create network access control policies that include identity-based policies, role-based policies, and attribute-based policies.
It is recommended the NAC have the capability to expose collected data on the assessed endpoints through an API that can be accessed externally, or the NAC solution must supply an SDK to allow customers to export data.
Admissions assessment filters should include, at a minimum, device attributes such as type, IP address, resource group, and/or mission conditions as defined in the NAC SSP. The NAC should also track the following to facilitate security investigations: when each device was last admitted/readmitted to the network; owning organization; owning organization's organizational unit; geographic location or the nearest network switch; motherboard serial number and BIOS; globally unique ID; and which unique network access compliance policies each device passed or failed during the latest network admission/readmission.
The client may be denied admission based on a returned posture token. In most NAC implementations, additional network access authorization policies can also be tied to the user's identity, but these features are out of scope for this STIG.
V-284582
high
Successful authentication must not automatically give an entity access to an asset or security boundary. The lack of authorization-based access control could result in the immediate compromise and unauthorized access to sensitive information.
Configure a Host Enforcer policy in Ivanti IPS to enforce compliance checks on endpoints that connect to the network. This is typically done to ensure the endpoints meet specific security standards and are up to date with their operating systems and patches. The policy can be applied at the realm level (pre-authentication) or at the role level (post-authentication) to manage access based on compliance. Additionally, configure Host Checker policies to perform health and security checks on endpoints, including antivirus versions, OS versions, and patch checker.
Configure a Host Enforcer policy in Ivanti IPS to enforce compliance checks on endpoints that connect to the network. This is typically done to ensure the endpoints meet specific security standards and are up to date with their operating systems and patches. The policy can be applied at the realm level (pre-authentication) or at the role level (post-authentication) to manage access based on compliance. Additionally, configure Host Checker policies to perform health and security checks on endpoints, including antivirus versions, OS versions, and patch checker.
V-284583
medium
Automated policy assessments must reflect the organization's current security policy so entry control decisions will happen only where remote endpoints meet the organization's security requirements. If the remote endpoints are allowed to connect to the organization's network without passing minimum-security controls, they become a threat to the entire network.
Organizational policy must be established for what the NAC will check on the host for the agent and agentless. Use a NAC system security plan (SSP) to assess compliance with the requirement since each SSP item must be configured.
Organizational policy must be established for what the NAC will check on the host for the agent and agentless. Use a NAC system security plan (SSP) to assess compliance with the requirement since each SSP item must be configured.
V-284586
medium
Automated and manual procedures for remediation for critical security updates are managed differently. Continuing to assess and remediate endpoints with risks that could endanger the network could impact network usage for all users. This isolation prevents traffic from flowing with traffic from endpoints that have been fully assessed and authorized. This solution provides a mechanism to detect and prevent unauthorized communication flow must be configured or provided as part of the system design. If information flow is not enforced based on approved authorizations, the system may become compromised. Information flow control regulates where information is allowed to travel within a system and between interconnected systems. Security attributes may be used to manage information flow control.
Unauthenticated devices must not be allowed to connect to remediation services. The Ivanti IPS and client does not need to provide IP transport for evaluation and remediation. However, using this Check and Fix text works as well.
This requirement also applies to Zero Trust initiatives.
Satisfies: SRG-NET-000015-NAC-000040, SRG-NET-000323-NAC-001233
Unauthenticated devices must not be allowed to connect to remediation services. The Ivanti IPS and client does not need to provide IP transport for evaluation and remediation. However, using this Check and Fix text works as well.
This requirement also applies to Zero Trust initiatives.
Satisfies: SRG-NET-000015-NAC-000040, SRG-NET-000323-NAC-001233
V-284587
medium
MAB can be defeated by spoofing the MAC address of a valid device. MAB enables port-based access control using the MAC address of the endpoint. A MAB-enabled port can be dynamically enabled or disabled based on the MAC address of the device that connects to it.
NPE devices that support PKI or an allowed authentication type must use PKI. MAB may be used for NPE that cannot support an approved device authentication. Nonentity endpoints include IoT devices, VoIP phones, and printers.
To support MAC authentication, add a MAC authentication server to Ivanti Policy Secure. Direct configuration of authenticators on the Ivanti Policy server, including MAC addresses, is not permitted; thus, NPE MACs must be associated with a MAC authentication server with an LDAP server.
NPE devices that support PKI or an allowed authentication type must use PKI. MAB may be used for NPE that cannot support an approved device authentication. Nonentity endpoints include IoT devices, VoIP phones, and printers.
To support MAC authentication, add a MAC authentication server to Ivanti Policy Secure. Direct configuration of authenticators on the Ivanti Policy server, including MAC addresses, is not permitted; thus, NPE MACs must be associated with a MAC authentication server with an LDAP server.
V-284588
medium
Denial-of-service (DoS) events may occur due to a variety of internal and external causes, such as an adversarial attack or a lack of planning to support organizational needs with respect to capacity and bandwidth. Such attacks can occur across a wide range of network protocols (e.g., IPv4, IPv6). A variety of technologies are available to limit or eliminate the origination and effects of DoS events. For example, boundary protection devices can filter certain types of packets to protect system components on internal networks from being directly affected by or the source of DoS attacks. Employing increased network capacity and bandwidth combined with service redundancy also reduces the susceptibility to DoS events.
V-285223
medium
Connections that bypass established security controls should only be used in cases of administrative need. These procedures and use cases must be approved by the information system security manager (ISSM).
V-285224
medium
Automated and manual procedures for remediation for critical security updates will be managed differently. Continuing to assess and remediate endpoints with risks that could endanger the network could impact network usage for all users.