Free DISA STIG and SRG Library | Vaulted

V-62165

The layer 2 switch must befail configured to faila securelysecure instate theif eventsystem ofinitialization anfails, operationalshutdown failurefails, or aborts fail.

Finding ID
SRG-NET-000235-L2S-000031
Rule ID
SV-76655r2_rule76655r1_rule
Severity
Cat II
CCE
(None)
Group Title
SRG-NET-000235
CCI
CCI-001126001190
Target Key
(None)
Documentable
No
Discussion

IfFailure theto switcha failsknown insafe anstate unsecurehelps mannerprevent (open),systems unauthorizedfrom trafficfailing originatingto externallya tostate thethat enclave may entercause orloss theof devicedata mayor permit unauthorized informationaccess release.to Fail secure is a condition achieved by employing information system mechanismsresources. toNetwork ensure,elements in the event of an operational failure of the switch, that itfail doessuddenly notand enterwith intono anincorporated unsecurefailure state whereplanning intendedmay securityleave properties no longer hold. If the devicehosting fails,system itavailable mustbut notwith fail in a mannerreduced thatsecurity willprotection allow unauthorized accesscapability. IfPreserving theinformation switchsystem failsstate forinformation anyalso reason,facilitates itsystem mustrestart stopand forwardingreturn trafficto altogether or maintain the configuredoperational securitymode policies.of If the deviceorganization stopswith forwardingless traffic,disruption maintainingto networkmission-essential availability would be achieved through device redundancyprocesses. An example is a firewall that blocks all traffic rather than allowing all traffic when a firewall component fails (e.g., fail closed and do not forward traffic). This prevents an attacker from forcing a failure of the system in order to obtain access. Abort refers to stopping a program or function before it has finished naturally. The term abort refers to both requested and unexpected terminations.

Fix Text

Configure the layer 2 switch to fail to a secure state upon failure of initialization, shutdown, or abort actions.

Check Content

Review the vendor documentation to determine if the layer 2 switch will fail to a secure state in the event that the system initialization fails, shutdown fails, or abort fails. If the layer 2 switch does not fail to a secure state in the event that the system initialization fails, shutdown fails, or abort fails, this is a finding.