UCF STIG Viewer Logo

For those instances where the organization requires encrypted traffic to be visible to information system monitoring tools, the application transmitting the encrypted traffic must make provisions to allow that traffic to be visible to specific system monitoring.


Overview

Finding ID Version Rule ID IA Controls Severity
V-35717 SRG-APP-000282-MAPP-NA SV-47004r1_rule Medium
Description
There is a recognized need to balance encrypting traffic versus the need to have insight into the traffic from a monitoring perspective. For some organizations, the need to ensure the confidentiality of traffic is paramount; for others, the mission-assurance concerns are greater. Rationale for non-applicability: The mobile application resides at a network endpoint. If it performs end-to-end encryption, then network traffic will not be visible to intermediate devices. IF there is a requirement for monitoring of this traffic, keys must be shared with the intermediate device. Achieving this capability is outside the scope of the mobile application, as the necessary modifications must be made to the intermediate device, not the end points.
STIG Date
Mobile Application Security Requirements Guide 2013-01-04

Details

Check Text ( C-44060r1_chk )
This requirement is NA for the MAPP SRG.
Fix Text (F-40260r1_fix)
The requirement is NA. No fix is required.