UCF STIG Viewer Logo

Enabling a connection that extends DISN IP network connectivity (e.g., NIPRNet and SIPRNet) to any DoD Vendor, Foreign, or Federal Mission Partner enclave or network without a signed DoD CIO approved sponsorship memo is prohibited. For classified connectivity it must be to a DSS approved contractor facility or DoD Component approved foreign government facility.


Overview

Finding ID Version Rule ID IA Controls Severity
V-14741 NET1826 SV-15497r2_rule High
Description
Having a circuit provisioned that connects the SIPRNet enclave to a non-DoD, foreign, or contractor network puts the enclave and the entire SIPRNet at risk. If the termination point is not operated by the government, there is no control to ensure that the network element at the remote facility is not compromised or connected to another network.
STIG Date
Network Infrastructure Policy Security Technical Implementation Guide 2016-12-22

Details

Check Text ( C-12963r3_chk )
Review the topology diagram of the classified network.

If there are any leased circuits connecting to DoD Vendor, Foreign, or Federal Mission Partner enclave or network without a signed DoD CIO-approved sponsorship memo, this is a finding.

If classified connectivity is not to a DSS-approved contractor facility or DoD Component-approved foreign government facility, this is a finding.
Fix Text (F-14207r2_fix)
Terminate all leased circuits connecting to DoD Vendor, Foreign, or Federal Mission Partner enclave or network without a signed DoD CIO-approved sponsorship memo.

Terminate all leased circuits for a classified network that is not connecting to a DSS-approved contractor facility or DoD Component-approved foreign government facility.