Network Device Management Rules : Ensuring applications implement cryptographic mechanisms
  
Ensuring applications implement cryptographic mechanisms
Rule Title: Applications used for nonlocal maintenance sessions must implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
STIG ID: RICX-DM-000135
Rule ID: SV-77473r1_rule Severity: CAT II
Vuln ID: V-62983 Class: Unclass
This requires the use of secure protocols instead of their unsecured counterparts, such as SSH instead of telnet, SCP instead of FTP, and HTTPS instead of HTTP. If unsecured protocols (lacking cryptographic mechanisms) are used for sessions, the contents of those sessions will be susceptible to eavesdropping, potentially putting sensitive data (including administrator passwords) at risk of compromise and potentially allowing hijacking of maintenance sessions.
Verifying applications implement cryptographic mechanisms
Verify that RiOS is configured to implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
For detailed information, see Verifying nonlocal maintenance is restricted.
Configuring applications to implement cryptographic mechanisms
Configure RiOS to implement cryptographic mechanisms to protect the confidentiality of nonlocal maintenance and diagnostic communications.
For detailed information, see Configuring the system so that nonlocal maintenance is restricted.