ASTi Telestra Target Operations & Maintenance Manual (Ver. 2, Rev. M)
Copyright © 2020 Advanced Simulation Technology inc.
27
6.2. DISA & STIGS
The Defense Information Systems Agency (DISA) develops and provides security configuration
guidance for IA and IA-enabled IT products. The guidelines are outlined in DISA's Security
Technical Implementation Guides (STIGS), which identify existing and potential vulnerabilities
on a system. STIGS exist for a variety of operating systems and applications. Additionally, there
are Security Readiness Review (SRR) scripts that automate the process of validating a system
configuration against the STIG requirements. Every security software version release for the
Target and Studio is tested against the latest versions of the UNIX STIG with UNIX SRR scripts.
Within each STIG there are four vulnerability code definitions from category I (high
vulnerability) to category IV (low vulnerability).
•
Category I
- Vulnerabilities that allow an attacker immediate access into a machine, allow
super user access, or bypass a firewall.
•
Category II
- Vulnerabilities that provide information that have a high potential of giving
access to an intruder.
•
Category III
- Vulnerabilities that provide information that potentially could lead to com-
promise.
•
Category IV
- Vulnerabilities that provide information that will lead to the possibility of
degraded security.
ASTi's goal for the Target and Studio is to eliminate all CAT I's and CAT II's and to minimize
CAT III and IV vulnerabilities. ASTi has also incorporated the UNIX SRR scripts into the
production testing process so that the software is constantly updated with the most valid security
enhancements
1
.
1
As the DISA STIG CAT I and II vulnerabilities change in future STIG releases it is impossible to predict future
issues. While ASTi will make every reasonable attempt to remove all CAT I and II issues we cannot guarantee
removal of all these issues. The CAT I and II issues are constantly changing over time. If removal of an issue is not
feasible we will work with the customer to obtain a waiver as required. This will be documented in the accompanying
ASTi SRR Report.