F5BI-AP-000199 - The BIG-IP APM must electronically verify PIV credentials when providing user authentication to virtual servers.

Information

The use of PIV credentials facilitates standardization and reduces the risk of unauthorized access.

DoD has mandated the use of the CAC to support identity management and personal authentication for systems covered under HSPD-12, as well as a primary component of layered protection for national security systems.

This requirement applies to ALGs that provide user authentication intermediary services.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM to electronically verify Personal Identity Verification (PIV) credentials.

See Also

http://iasecontent.disa.mil/stigs/zip/U_F5_BIG-IP_Access_Policy_Manager_11-x_V1R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(12), CAT|II, CCI|CCI-001954, Rule-ID|SV-74483r1_rule, STIG-ID|F5BI-AP-000199, Vuln-ID|V-60053

Plugin: F5

Control ID: 280bb4123481a5ea5512227a048fe55941541c0af263529fa3bea28ea79e404a