Connections between the DoD enclave and the Internet or other public or commercial wide area networks must require a DMZ.

Overview

Finding IDVersionRule IDIA ControlsSeverity
V-222671APSC-DV-003350SV-222671r961863_ruleCCI-001119medium
Description
In order to protect DoD data and systems, all remote access to DoD information systems must be mediated through a managed access control point, such as a remote access server in a DMZ.
STIGDate
Application Security and Development Security Technical Implementation Guide2025-02-12

Related Frameworks

2 paths across 2 frameworks
NIST 800-531 mapping
  • DISA · 6 · disa_xccdf · related
  • DISA · 2025-01-23 · disa_cci_list · equivalent
CCI1 mapping
CCI-001119
1.00
  • DISA · 6 · disa_xccdf · related

Details

Check Text (C-222671r961863_chk)

Interview the application representative and determine if the application is publicly accessible. If the application is publicly accessible and traffic is not being routed through a DMZ, this is a finding.

Fix Text (F-24330r493922_fix)

Setup a DMZ between DoD and public networks.