Free DISA STIG and SRG Library | Vaulted

V-28784

A service or feature that calls home to the vendor must be disabled.

Finding ID
NET0405
Rule ID
SV-36774r4_rule
Severity
Cat II
CCE
(None)
Group Title
Call home service is disabled.
CCI
(None)
Target Key
(None)
Documentable
No
Discussion

Call home services or features will routinely send data such as configuration and diagnostic information to the vendor for routine or emergency analysis and troubleshooting. The risk that transmission of sensitive data sent to unauthorized persons could result in data loss or downtime due to an attack.

Fix Text

Configure the network device to disable the call home service or feature.

Check Content

Review the device configuration to determine if the call home service or feature is disabled on the device. If the call home service is enabled on the device, this is a finding.

Responsibility

Information Assurance Officer