STIGhubSTIGhub
STIGhub— A free STIG search and compliance tool·STIGs updated 12 hours ago
Powered by Pylon·Privacy·Terms·Feedback·© 2026 Beacon Cloud Solutions, Inc.
← Back to General Application (GAPP) Security Requirements Guide

V-288250

CAT II (Medium)

The application must use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of remote access sessions.

Rule ID

SV-288250r1252948_rule

STIG

General Application (GAPP) Security Requirements Guide

Version

V1R0.1

CCIs

CCI-002450CCI-003123

Discussion

Without confidentiality protection mechanisms, unauthorized individuals may gain access to sensitive information via a remote access session. Remote access is access to DoW nonpublic information systems by an authorized user (or an information system) communicating through an external, nonorganization-controlled network. A block cipher mode is an algorithm that features the use of a symmetric key block cipher algorithm to provide an information service, such as confidentiality or authentication. AES is the FIPS-validated cipher block cryptographic algorithm approved for use in DoW. For an algorithm implementation to be listed on a FIPS 140-3 cryptographic module validation certificate as an approved security function, the algorithm implementation must meet all the requirements of FIPS 140-3 and must successfully complete the cryptographic algorithm validation process. Currently, NIST has approved the following confidentiality modes to be used with approved block ciphers in a series of special publications: ECB, CBC, OFB, CFB, CTR, XTS-AES, FF1, FF3, CCM, GCM, KW, KWP, and TKW. This requirement pertains to Zero Trust.

Check Content

Review the application documentation and deployed configuration to determine whether the application's cryptography mechanism uses FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of remote access sessions.

If the application's cryptography mechanism does not use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of remote access sessions, this is a finding.

Fix Text

Navigate to the cryptography configuration within the application.

Configure the application's cryptography mechanism to use FIPS-validated cryptographic algorithms defined in CNSSP 15 Annex B to protect the integrity and confidentiality of remote access sessions.