F5BI-LT-000197 - The BIG-IP Core implementation providing user authentication intermediary services must accept Personal Identity Verification (PIV) credentials when providing user authentication to virtual servers.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

The use of PIV credentials facilitates standardization and reduces the risk of unauthorized access.

DoD has mandated the use of the CAC to support identity management and personal authentication for systems covered under HSPD 12, as well as a primary component of layered protection for national security systems.

This requirement applies to ALGs that provide user authentication intermediary services.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

If user authentication intermediary services are provided, configure the BIG-IP Core as follows:

Configure a policy in the BIG-IP APM module to accept Personal Identity Verification (PIV) credentials when providing user authentication.

Apply APM policy to the applicable Virtual Server(s) in the BIG-IP LTM module to accept Personal Identity Verification (PIV) credentials when providing user authentication to virtual servers.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_F5_BIG-IP_Local_Traffic_Manager_11-x_V1R3_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-2(12), CAT|II, CCI|CCI-001953, Rule-ID|SV-74775r1_rule, STIG-ID|F5BI-LT-000197, Vuln-ID|V-60345

Plugin: F5

Control ID: bff0352b89b8dcc48323066f5714af76c96bfea568149b760a9440648f4b2f9a