F5 BIG-IP Access Policy Manager 11.x Security Technical Implementation Guide
Pick two releases to diff their requirements.
Open a previous version of this STIG.
- RMF Control
- AC-3
- Severity
- M
- CCI
- CCI-000213
- Version
- F5BI-AP-000003
- Vuln IDs
-
- V-59929
- Rule IDs
-
- SV-74359r1_rule
Checks: C-60619r2_chk
If the BIG-IP APM module does not provide user access control intermediary services as part of the traffic management functions of the BIG-IP Core, this is not applicable. Verify the BIG-IP APM module is configured to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles >> Access Profiles List. Review Access Policy Profiles to verify configuration for authorization by employing identity-based, role-based, and/or attribute-based security policies. If the BIG-IP APM is not configured to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies, this is a finding.
Fix: F-65339r1_fix
If user access control intermediary services are provided as part of the traffic management functions of the BIG-IP Core, configure the BIG-IP APM module to enforce approved authorizations for logical access to information and system resources by employing identity-based, role-based, and/or attribute-based security policies.
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000048
- Version
- F5BI-AP-000023
- Vuln IDs
-
- V-59931
- Rule IDs
-
- SV-74361r1_rule
Checks: C-60621r1_chk
If the BIG-IP APM module does not provide user access control intermediary services as part of the traffic management functions of the BIG-IP Core, this is not applicable. Verify the BIG-IP APM module is configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to virtual servers. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access. If the BIG-IP APM module is not configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to the virtual servers, this is a finding.
Fix: F-65341r1_fix
If user access control intermediary services are provided as part of the traffic management functions of the BIG-IP Core, configure an access policy in the BIG-IP APM module to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to virtual servers.
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-000050
- Version
- F5BI-AP-000025
- Vuln IDs
-
- V-59933
- Rule IDs
-
- SV-74363r1_rule
Checks: C-60623r1_chk
If the BIG-IP APM module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and takes explicit actions to log on for further access. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users accessing virtual servers acknowledge the usage conditions and take explicit actions to log on for further access. If the BIG-IP APM module is not configured to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access, this is a finding.
Fix: F-65343r1_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to retain the Standard Mandatory DoD-approved Notice and Consent Banner on the screen until users acknowledge the usage conditions and take explicit actions to log on for further access.
- RMF Control
- AC-8
- Severity
- L
- CCI
- CCI-001384
- Version
- F5BI-AP-000027
- Vuln IDs
-
- V-60025
- Rule IDs
-
- SV-74455r1_rule
Checks: C-60705r1_chk
If the BIG-IP APM module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications. If the BIG-IP APM module is not configured to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications, this is a finding.
Fix: F-65435r1_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to display the Standard Mandatory DoD-approved Notice and Consent Banner before granting access to publicly accessible applications.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- F5BI-AP-000073
- Vuln IDs
-
- V-60027
- Rule IDs
-
- SV-74457r1_rule
Checks: C-60707r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). If the BIG-IP APM is not configured to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users), this is a finding.
Fix: F-65437r1_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- F5BI-AP-000075
- Vuln IDs
-
- V-60029
- Rule IDs
-
- SV-74459r1_rule
Checks: C-60709r1_chk
If the BIG-IP APM module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured with a pre-established trust relationship and mechanisms with appropriate authorities (e.g., Active Directory or AAA server) that validate user account access authorizations and privileges. If the BIG-IP APM is not configured with a pre-established trust relationship and mechanisms with appropriate authorities that validate each user access authorization and privileges, this is a finding.
Fix: F-65439r1_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module with a pre-established trust relationship and mechanisms with appropriate authorities that validate each user access authorization and privileges.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000764
- Version
- F5BI-AP-000077
- Vuln IDs
-
- V-60031
- Rule IDs
-
- SV-74461r1_rule
Checks: C-60711r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to restrict user authentication traffic to specific authentication server(s). If the BIG-IP APM module is not configured to restrict user authentication traffic to a specific authentication server(s), this is a finding.
Fix: F-65441r1_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to restrict user authentication traffic to specific authentication server(s).
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-000766
- Version
- F5BI-AP-000079
- Vuln IDs
-
- V-60033
- Rule IDs
-
- SV-74463r1_rule
Checks: C-60713r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM is configured to use multifactor authentication for network access to non-privileged accounts. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for granting access. Verify the Access Profile is configured to use multifactor authentication for network access to non-privileged accounts. If the BIG-IP APM module is not configured to use multifactor authentication for network access to non-privileged accounts, this is a finding.
Fix: F-65443r1_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to use multifactor authentication for network access to non-privileged accounts.
- RMF Control
- IA-5
- Severity
- M
- CCI
- CCI-000187
- Version
- F5BI-AP-000085
- Vuln IDs
-
- V-60035
- Rule IDs
-
- SV-74465r1_rule
Checks: C-60715r1_chk
If the BIG-IP APM module does not provide PKI-based, user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module maps the authenticated identity to the user account for PKI-based authentication. Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for PKI-based authentication. Verify the Access Profile is configured to map the authenticated identity to the user account for PKI-based authentication. If the BIG-IP APM module does not map the authenticated identity to the user account for PKI-based authentication, this is a finding.
Fix: F-65445r1_fix
If the BIG-IP APM module provides PKI-based, user authentication intermediary services, configure a profile in the BIG-IP APM module to map the authenticated identity to the user account for PKI-based authentication.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-000804
- Version
- F5BI-AP-000087
- Vuln IDs
-
- V-60037
- Rule IDs
-
- SV-74467r1_rule
Checks: C-60717r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services to non-organizational users, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used to identify and authenticate non-organizational users. Verify the Access Profile is configured to uniquely identify and authenticate non-organizational users. If the BIG-IP APM module is not configured to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users) when connecting to virtual servers, this is a finding.
Fix: F-65447r1_fix
If the BIG-IP APM module provides user authentication intermediary services to non-organizational users, configure a profile in the BIG-IP APM module to uniquely identify and authenticate non-organizational users (or processes acting on behalf of non-organizational users) when connecting to virtual servers.
- RMF Control
- AC-12
- Severity
- M
- CCI
- CCI-002361
- Version
- F5BI-AP-000147
- Vuln IDs
-
- V-60039
- Rule IDs
-
- SV-74469r1_rule
Checks: C-60719r1_chk
If the BIG-IP Am module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for organizational access. Verify the Access Profile is configured to automatically terminate user sessions when organization-defined conditions or trigger events occur that require a session disconnect. If the BIG-IP APM module is not configured to automatically terminate a user session when organization-defined conditions or trigger events occur that require a session disconnect, this is a finding.
Fix: F-65449r1_fix
If user access control intermediary services are provided, configure an access policy in the BIG-IP APM module to automatically terminate a user session when organization-defined conditions or trigger events occur that require a session disconnect.
- RMF Control
- AC-12
- Severity
- L
- CCI
- CCI-002364
- Version
- F5BI-AP-000151
- Vuln IDs
-
- V-60041
- Rule IDs
-
- SV-74471r1_rule
Checks: C-60721r1_chk
If the BIG-IP APM module does not provide user access control intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for connecting to virtual servers. Verify the Access Profile is configured to display an explicit logoff message to users, indicating the reliable termination of authenticated communications sessions. If the BIG-IP APM module is not configured to display an explicit logoff message to users indicating the reliable termination of authenticated communications sessions, this is a finding.
Fix: F-65451r1_fix
If user access control intermediary services are provided, configure the BIG-IP APM module to display an explicit logoff message to users indicating the reliable termination of authenticated communications sessions.
- RMF Control
- AC-17
- Severity
- M
- CCI
- CCI-002314
- Version
- F5BI-AP-000153
- Vuln IDs
-
- V-60043
- Rule IDs
-
- SV-74473r1_rule
Checks: C-60723r1_chk
If the BIG-IP APM module does not serve as an intermediary for remote access traffic (e.g., web content filter, TLS and webmail), this is not applicable. Verify the BIG-IP APM module is configured to control remote access methods. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for managing remote access. Verify the Access Profile is configured to control remote access methods. If the BIG-IP APM module is not configured to control remote access methods, this is a finding.
Fix: F-65453r1_fix
If intermediary services for remote access communications traffic are provided, configure the BIG-IP APM module to control remote access methods.
- RMF Control
- IA-11
- Severity
- M
- CCI
- CCI-002038
- Version
- F5BI-AP-000191
- Vuln IDs
-
- V-60045
- Rule IDs
-
- SV-74475r1_rule
Checks: C-60725r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for organizational access. Verify the Access Profile is configured to require users to re-authenticate when organization-defined circumstances or situations require re-authentication. If the BIG-IP APM module is not configured to require users to re-authenticate when organization-defined circumstances or situations require re-authentication, this is a finding.
Fix: F-65455r1_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to require users to re-authenticate when organization-defined circumstances or situations require re-authentication.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001951
- Version
- F5BI-AP-000193
- Vuln IDs
-
- V-60047
- Rule IDs
-
- SV-74477r1_rule
Checks: C-60727r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for remote access for non-privileged accounts. Verify the Access Profile is configured to require multifactor authentication for remote access with non-privileged accounts. If the BIG-IP APM module is not configured to require multifactor authentication for remote access to non-privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access, this is a finding.
Fix: F-65457r1_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to require multifactor authentication for remote access to non-privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001948
- Version
- F5BI-AP-000195
- Vuln IDs
-
- V-60049
- Rule IDs
-
- SV-74479r1_rule
Checks: C-60729r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for remote access for privileged accounts. Verify the Access Profile is configured to require multifactor authentication for remote access with privileged accounts. If the BIG-IP APM module is not configured to require multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access, this is a finding.
Fix: F-65459r1_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to require multifactor authentication for remote access to privileged accounts in such a way that one of the factors is provided by a device separate from the system gaining access.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001953
- Version
- F5BI-AP-000197
- Vuln IDs
-
- V-60051
- Rule IDs
-
- SV-74481r1_rule
Checks: C-60731r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for user authentication. Verify the Access Profile is configured to accept Personal Identity Verification (PIV) credentials when providing user authentication. If the BIG-IP APM module is not configured to accept Personal Identity Verification (PIV) credentials, this is a finding.
Fix: F-65461r1_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM module to accept Personal Identity Verification (PIV) credentials.
- RMF Control
- IA-2
- Severity
- M
- CCI
- CCI-001954
- Version
- F5BI-AP-000199
- Vuln IDs
-
- V-60053
- Rule IDs
-
- SV-74483r1_rule
Checks: C-60733r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used for user authentication. Verify the Access Profile is configured to electronically verify Personal Identity Verification (PIV) credentials when providing user authentication If the BIG-IP APM module is not configured to electronically verify Personal Identity Verification (PIV) credentials, this is a finding.
Fix: F-65463r1_fix
If user authentication intermediary services are provided, configure an access policy in the BIG-IP APM to electronically verify Personal Identity Verification (PIV) credentials.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-002009
- Version
- F5BI-AP-000205
- Vuln IDs
-
- V-60055
- Rule IDs
-
- SV-74485r1_rule
Checks: C-60735r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services to non-organizational users, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used to identify and authenticate users from other federal agencies. Verify the Access Profile is configured to accept Personal Identity Verification (PIV) credentials from other federal agencies. If the BIG-IP APM module is not configured to accept Personal Identity Verification (PIV) credentials from other federal agencies, this is a finding.
Fix: F-65465r1_fix
If the BIG-IP APM module provides user authentication intermediary services to non-organizational users, configure a profile in the BIG-IP APM module to accept Personal Identity Verification (PIV) credentials from those federal agencies.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-002010
- Version
- F5BI-AP-000207
- Vuln IDs
-
- V-60057
- Rule IDs
-
- SV-74487r1_rule
Checks: C-60737r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services to non-organizational users, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used to identify and authenticate non-organizational users. Verify the Access Profile is configured to electronically verify Personal Identity Verification (PIV) credentials from other federal agencies. If the BIG-IP APM module is not configured to electronically verify Personal Identity Verification (PIV) credentials from other federal agencies, this is a finding.
Fix: F-65467r1_fix
If the BIG-IP APM module provides user authentication intermediary services to non-organizational users, configure a profile in the BIG-IP APM module to electronically verify Personal Identity Verification (PIV) credentials from other federal agencies.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-002011
- Version
- F5BI-AP-000209
- Vuln IDs
-
- V-60059
- Rule IDs
-
- SV-74489r1_rule
Checks: C-60739r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services to non-organizational users, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used to identify and authenticate non-organizational users. Verify the Access Profile is configured to accept FICAM-approved third-party credentials. If the BIG-IP APM module is not configured to accept FICAM-approved third-party credentials, this is a finding.
Fix: F-65469r1_fix
If the BIG-IP APM module provides user authentication intermediary services to non-organizational users, configure a profile in the BIG-IP APM module to accept FICAM-approved third-party credentials.
- RMF Control
- IA-8
- Severity
- M
- CCI
- CCI-002014
- Version
- F5BI-AP-000211
- Vuln IDs
-
- V-60061
- Rule IDs
-
- SV-74491r1_rule
Checks: C-60741r1_chk
If the BIG-IP APM module does not provide user authentication intermediary services to non-organizational users, this is not applicable. Verify the BIG-IP APM module is configured as follows: Navigate to the BIG-IP System manager >> Access Policy >> Access Profiles. Click "Edit..." in the "Access Policy" column for an Access Profile used to identify and authenticate non-organizational users. Verify the Access Profile is configured to conform to FICAM-issued profiles. If the BIG-IP APM module is not configured to conform to FICAM-issued profiles, this is a finding.
Fix: F-65471r1_fix
If the BIG-IP APM module provides user authentication intermediary services to non-organizational users, configure a profile in the BIG-IP APM module that conforms to FICAM-issued profiles.
- RMF Control
- SI-10
- Severity
- M
- CCI
- CCI-002754
- Version
- F5BI-AP-000229
- Vuln IDs
-
- V-60063
- Rule IDs
-
- SV-74493r1_rule
Checks: C-60743r1_chk
Verify the BIG-IP APM module is configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives. This can be demonstrated by the SA sending an invalid input to a virtual server. Provide evidence that the virtual server was able to handle the invalid input and maintain operation. If the BIG-IP APM module is not configured to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives, this is a finding.
Fix: F-65473r1_fix
Configure the BIG-IP APM module to handle invalid inputs in a predictable and documented manner that reflects organizational and system objectives.