GEN005580 - A system used for routing must not run other network services or applications.

Information

Installing extraneous software on a system designated as a dedicated router poses a security threat to the system and the network. Should an attacker gain access to the router through the unauthorized software, the entire network is susceptible to malicious activity.

Solution

Ensure only authorized software is loaded on a designated router. Authorized software will be limited to the most current version of routing protocols and SSH for system administration purposes.

See Also

https://iasecontent.disa.mil/stigs/zip/U_AIX_6-1_V1R13_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-4, 800-53|SC-5, CAT|II, CCI|CCI-001208, Group-ID|V-4398, Rule-ID|SV-4398r2_rule, STIG-ID|GEN005580

Plugin: Unix

Control ID: 25091caa6e4372c4c46dc5a67b2e28903f14b170957a17130b84414417caaa99