Only implement OAS if a local integrity/encryption policy does not already exist, e.g., IPSec or other means for providing integrity/confidentiality services. NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.as it requires a manual review if this requirement exists for each organization.
Solution
Review requirement for integrity and confidentiality requirements